> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xorlab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Pages under /latest/ document the current release. Paths that begin with a version number, for example /10.0/, are frozen snapshots of superseded releases kept for reference only — never present their instructions as current. If the reader's version is unknown, answer from /latest/ and say which version the answer describes.
> xorlab is deployed on-premises, hybrid, or as a cloud service, and integrates with either Microsoft 365 or on-premises mail infrastructure. Configuration steps often differ between these. State which deployment and integration mode an instruction applies to instead of presenting one as universal.
> Distinguish inline mode from monitoring mode when describing anything that acts on email. Monitoring mode observes a copy and cannot block or quarantine; inline mode routes mail through xorlab and can.
> Write the product name as lowercase 'xorlab'. Use the documented component names: xorlab Control Center (XCC), xorlab MTA, xorlab Sandbox (DANA), xorlab Natural Language Understanding (NLU). After the first mention, use the short forms XCC, MTA, Sandbox, and NLU. Do not use DANA as a standalone name for the Sandbox, but keep it where it is a literal string in configuration keys, container names, and hostnames.
> Do not invent configuration keys, rule parameters, list names, log properties, or API fields. If a value is not present in this documentation, say that it is not documented rather than guessing.

# Quick Walkthrough

> A hands-on tour of the most important xorlab features. Read the core concepts first.

If you prefer to watch a video instead, have a look at [Video Tutorials ](/latest/video-tutorials).

We recommend to have read the [Core Concepts](/latest/concepts-overview) before starting with the walkthrough here.

In 15 minutes, you will cover the basics of using xorlab:

* How to search for emails
* Create your first campaign
* Using the similarity search
* Give feedback to a reported email

## Search an email

The search is very powerful and one of the key tools in xorlab. The full search syntax can be found under [Search](/latest/search).

1. Open the **Messages** menu on the left.

2. Search for all sender addresses that contain the word `notification`: Open the **Sender** filter, switch the dropdown to **contains** and add `notification`. If you don't get any results, you can choose any other word.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/search-sender.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=e0217bdc744ded25c0ce72ed005c1023" alt="Sender search" width="897" height="372" data-path="latest/assets/search-sender.png" />

3. Refine the search further by adding some [Tags](/latest/tags) to only match incoming emails from untrusted senders: `#untrusted #inc`. You can add as many tags as you want. By default, they are ANDed.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/search-sender-tag.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=43c394aa38d2c85efd2ca87c71d82064" alt="Sender search tags" width="1178" height="311" data-path="latest/assets/search-sender-tag.png" />

4. All filters can be replaced by text search. The following gives the same results as above:

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/search-sender-tag-all.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=e1ff1254934d089dc9c24ff50fac9ff8" alt="Sender search tags text" width="927" height="267" data-path="latest/assets/search-sender-tag-all.png" />

5. You can further play around using for example:

   * `(topic:invoice OR topic:accountissue) #newsender`: Unknown senders that send emails about invoices or account issues
   * `#untrusted #vbascript`: Emails from untrusted senders with VBA script
   * `#partner #encryptedarchive`: Emails from partners that contain an encrypted archive

6. Save your search for later use with the button on the right side. You can find all your saved searches in the **Saved Searches** menu.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/search-saved.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=ee9b154aea3a917bc1bafd2df5b534cf" alt="Saved searches" width="929" height="234" data-path="latest/assets/search-saved.png" />

## Create a campaign

Campaigns allow you to define an action for all emails that match a search query. It is an easy tool to react to missed threats or false positives.

Campaigns work only forward-looking, and do not affect past emails. For an in-depth guide about Campaigns, check out [Using Campaigns](/latest/campaigns).

1. Create a new search query that will be the basis of the campaign: `#youngsender #newsender topic:packagedelivery`. This will find all emails from recently registered domains that talk about package delivery.

2. Click on the campaign button on the right side in the search.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/campaign-create.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=815b1fdfc08bf6ce3cffd00a2aa6790f" alt="Create campaign" width="1196" height="247" data-path="latest/assets/campaign-create.png" />

3. Enter a descriptive campaign name.

4. Under **Message Action**, you can choose the action that should be applied to all emails that will match this search from now on. Choose **None** for now, in this way the campaign will be passive and not have any impact. The **Resolve Action** can also be left as **None** as it affects only [Reported Emails](/latest/abuse-mailbox).

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/campaign-create-dialog.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=c40243ef0722ea3814fd7dddc2bc012e" alt="Create campaign dialog" width="1124" height="646" data-path="latest/assets/campaign-create-dialog.png" />

   <Note>
     **Deliver**

     Be careful when using the Deliver action. It will overwrite all built-in detection mechanisms. It is normally only used in a very narrow scope to address false positives.
   </Note>

5. After saving, you can find your new campaign in the **Campaign** menu on the left. The switch in the upper right provides different views for convenience.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/campaign-overview.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=0603c66f4d6e758e45b538f095f3dc09" alt="Campaign overview" width="1201" height="575" data-path="latest/assets/campaign-overview.png" />

6. If you want to activate the campaign, you can set the **Message Action** any time later to **Quarantine**.

## Using the similarity search

The similarity search allows to group emails based on different parameters. For example, a phishing wave might use different sender addresses and subjects, but you can still group them based on content similarity.

1. In the **Messages** menu, click on any email in the list to open the [Detail View](/latest/understand-verdict).

2. Open the **SIMILAR** tab. This will show you all emails with a similar content. The first email highlighted in blue is the one that you opened in the detail view.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/detail-view-similar.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=4a6e354b13568546e9bccb0cfd0c9b34" alt="Similar view" width="1511" height="933" data-path="latest/assets/detail-view-similar.png" />

   <Note>
     **Content similarity**

     The content similarity uses fuzzy hashing of the email body to group emails. It is robust such that one can change several words of an email and even re-arrange paragraphs and it will still group them together. The false positive rate is generally very low for emails with enough text (above 30-40 words).
   </Note>

3. If your email does not have any results based on content similarity, you can use one of the other built-in groupings like **Same Sender**. The number in brackets shows the amount of matches.

   * When choosing another grouping, you need to disable the **Content similar** search, otherwise they will be ANDed.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/detail-view-similar2.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=e00973596ef00b1b8bf4ebd8bbf106d7" alt="Similar view 2" width="1441" height="339" data-path="latest/assets/detail-view-similar2.png" />

4. When you found a grouping that works for you, you can create again a saved search or even a campaign with the two icons on the right side in the search bar.

5. The search bar here supports the same searches as the default one in the **Messages** menu. For example, you can refine the built-in groupings with normal search queries. In this example we grouped the emails based on display name and restricted it via search `verdict:phishing` to only phishing emails.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/detail-view-similar3.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=a215c54f90710400df22da50d14930a0" alt="Similar view 3" width="1518" height="633" data-path="latest/assets/detail-view-similar3.png" />

## Give feedback to a reported email

<Warning>
  **Prerequisites**

  * This chapter is only applicable if you use the [Abuse Mailbox](/latest/abuse-mailbox) feature of xorlab.
  * You need at least one already reported email in xorlab.
</Warning>

Here we show how you find the user reported emails and give feedback to the reporter.

1. Open the **Abuse Mailbox** menu on the left and choose **All Cases**. This will show all reported emails xorlab received.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/abuse-mailbox.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=b84140bfc443be90b97ea018a223e698" alt="Abuse Mailbox" width="300" data-path="latest/assets/abuse-mailbox.png" />

2. The search bar on top works in the same way as the ones we've seen in the previous chapters. Optional: You can additionally use the `reporter:` keyword to search for specific internal reporters.

3. Click on an email where the **STATUS** on the right side is `OPEN`.

4. You will see the same detail view as before, but additionally you have **Resolve** buttons in the upper right. Click on **Resolve as Spam**.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/abuse-mailbox2.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=28bab1f09cf1734728f67863e2fad75f" alt="Abuse Mailbox detail view" width="1462" height="274" data-path="latest/assets/abuse-mailbox2.png" />

5. Under **Feedback Template** you can select what feedback the reporter should get. Keep it as *Spam*. Add a custom **Comment**, and click on **Resolve**.

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/abuse-mailbox3.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=20f94ac07e8597e867e79c348e7ede27" alt="Abuse Mailbox dialog" width="600" data-path="latest/assets/abuse-mailbox3.png" />

   <Note>
     **Attaching the reported email**

     When you select a benign verdict (shown as green in the search), xorlab will attach the reported email as EML to the feedack email. For malicious emails, this is not the case.
   </Note>

6. A few seconds later, the reporter will now get a feedback email like this. The comment is added in the lower half of the email:

   <img src="https://mintcdn.com/xorlab/O_O2TUa6eRBR54aI/latest/assets/abuse-mailbox-feedback.png?fit=max&auto=format&n=O_O2TUa6eRBR54aI&q=85&s=ce353ce1b6e565ecb397121a2e5dd626" alt="Abuse Mailbox feedback" width="600" data-path="latest/assets/abuse-mailbox-feedback.png" />
