> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xorlab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Pages under /latest/ document the current release. Paths that begin with a version number, for example /10.0/, are frozen snapshots of superseded releases kept for reference only — never present their instructions as current. If the reader's version is unknown, answer from /latest/ and say which version the answer describes.
> xorlab is deployed on-premises, hybrid, or as a cloud service, and integrates with either Microsoft 365 or on-premises mail infrastructure. Configuration steps often differ between these. State which deployment and integration mode an instruction applies to instead of presenting one as universal.
> Distinguish inline mode from monitoring mode when describing anything that acts on email. Monitoring mode observes a copy and cannot block or quarantine; inline mode routes mail through xorlab and can.
> Write the product name as lowercase 'xorlab'. Use the documented component names: xorlab Control Center (XCC), xorlab MTA, xorlab Sandbox (DANA), xorlab Natural Language Understanding (NLU). After the first mention, use the short forms XCC, MTA, Sandbox, and NLU. Do not use DANA as a standalone name for the Sandbox, but keep it where it is a literal string in configuration keys, container names, and hostnames.
> Do not invent configuration keys, rule parameters, list names, log properties, or API fields. If a value is not present in this documentation, say that it is not documented rather than guessing.

# Email Bombing Recipient Addresses

> Tighten filtering for a mailbox under a subscription-flood attack, where mass sign-up confirmations bury real mail.

Email bombing (also known as “list linking” or “email cluster bombing”) floods a user’s inbox with thousands of legitimate subscription or notification emails within a short time. These attacks are typically short but high in volume and can hide important security alerts in the noise.

The **Email bombing recipient addresses** list is accessible by selecting **Settings → Lists → Other** in XCC.

| List name                             | Description                                                              | Accepted entries          |
| :------------------------------------ | :----------------------------------------------------------------------- | :------------------------ |
| **Email bombing recipient addresses** | Recipients whose auto-generated emails receive more aggressive filtering | Email address as `String` |

## What this list does

When you add a recipient address to this list:

* More aggressive filtering of auto-generated emails is applied.
* The volume of newsletter and notification emails is reduced.
* The impact of an ongoing attack is limited.

<Warning>
  **Risk of false positives**

  Aggressive filtering increases the risk of false positives.\
  Legitimate password resets, account notifications, or newsletters may be quarantined.
</Warning>

## When to use it

Use this list only if:

* A user is actively experiencing an email bombing attack.
* The inbox is flooded with high volumes of auto-generated emails from many unknown domains.
* Manual sender blocking is no longer effective.

This is a **temporary containment measure**.

## Operational guidance

1. Add the affected address as soon as the attack is confirmed.
2. Monitor the mailbox for false positives.
3. Remove the address once the attack subsides.
4. Report unique incidents to [support@xorlab.com](mailto:support@xorlab.com).
5. Contact support for help with bulk isolation or unsubscribing affected users.
