Skip to main content
In the following code blocks, <sender-address> can be a full email address, or just a mailbox such as notification or notification@ — in that case, it is completed using the tenant’s primary guarded domain, the first entry under domains for that tenant in guarded_tenants.yml. If you leave the setting out entirely, the default shown in each section below applies.

Feedback emails

Feedback emails are sent after a user reports a suspicious email. They can be manually triggered by an analyst through resolving a case as well as automatically generated through a campaign or an auto-close rule. By default, these emails are sent from notification@<domain>, with <domain> referring to the tenant’s primary domain. If you like to customize the sender address, add the following block (if it does not already exist) to the corresponding tenant or config set in shared/guarded_tenants.yml:
guarded_tenants.yml
Afterward, click Publish. The new configuration becomes active within about one minute.

SMTP auth for feedback emails

If you want the feedback emails to be sent to an SMTP server requiring authentication, please follow the steps outlined in SMTP auth for specific email addresses.

Quarantine notifications

Quarantine notifications are sent to the end-user when an email addressed to them has been put in quarantine, and this is also the sender address used for quarantine digests. By default, these emails are sent from quarantine@<domain>, with <domain> referring to the tenant’s primary domain. If you like to customize the sender address, add the following block (if it does not already exist) to the corresponding tenant or config set in shared/guarded_tenants.yml:
guarded_tenants.yml
Afterward, click Publish. The new configuration becomes active within about one minute.

Custom bounce and notification messages

The xorlab Security Platform rule language allows configuring custom bounce or notification messages that are triggered for certain events (for example, when using the rule context keys SenderNotification.Template or ReceiverNotification.Template). These emails share the sender address configured for feedback emails: by default notification@<domain>, and customizable through the same emailReporting.notificationAddress property in shared/guarded_tenants.yml.