> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xorlab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Pages under /latest/ document the current release. Paths that begin with a version number, for example /10.0/, are frozen snapshots of superseded releases kept for reference only — never present their instructions as current. If the reader's version is unknown, answer from /latest/ and say which version the answer describes.
> xorlab is deployed on-premises, hybrid, or as a cloud service, and integrates with either Microsoft 365 or on-premises mail infrastructure. Configuration steps often differ between these. State which deployment and integration mode an instruction applies to instead of presenting one as universal.
> Distinguish inline mode from monitoring mode when describing anything that acts on email. Monitoring mode observes a copy and cannot block or quarantine; inline mode routes mail through xorlab and can.
> Write the product name as lowercase 'xorlab'. Use the documented component names: xorlab Control Center (XCC), xorlab MTA, xorlab Sandbox (DANA), xorlab Natural Language Understanding (NLU). After the first mention, use the short forms XCC, MTA, Sandbox, and NLU. Do not use DANA as a standalone name for the Sandbox, but keep it where it is a literal string in configuration keys, container names, and hostnames.
> Do not invent configuration keys, rule parameters, list names, log properties, or API fields. If a value is not present in this documentation, say that it is not documented rather than guessing.

# Rule Parameters

> The low-level knobs behind the Actions screen, with the suffix conventions for inbound and outbound defense.

Normally, these parameters do not need to be used directly, instead one can use the [Actions](/latest/detection-actions) configuration screen.

## Parameters for email classification

<Accordion title="Available parameters">
  ```shell theme={null}
  BEC_decision_action
  BEC_decision_email_screenshot
  BEC_decision_keep_dana_assets
  BEC_decision_notify_user
  BEC_decision_subject_rewrite
  EXTORTION_decision_action
  EXTORTION_decision_email_screenshot
  EXTORTION_decision_keep_dana_assets
  EXTORTION_decision_notify_user
  EXTORTION_decision_subject_rewrite
  BLACKLIST_decision_action
  BLACKLIST_decision_email_screenshot
  BLACKLIST_decision_keep_dana_assets
  BLACKLIST_decision_notify_user
  BLACKLIST_decision_subject_rewrite
  FILTER_high_confidence_decision_action
  FILTER_high_confidence_decision_email_screenshot
  FILTER_high_confidence_decision_keep_dana_assets
  FILTER_high_confidence_decision_notify_user
  FILTER_high_confidence_decision_subject_rewrite
  FILTER_medium_confidence_decision_action
  FILTER_medium_confidence_decision_email_screenshot
  FILTER_medium_confidence_decision_keep_dana_assets
  FILTER_medium_confidence_decision_notify_user
  FILTER_medium_confidence_decision_subject_rewrite
  FILTER_low_confidence_decision_action
  FILTER_low_confidence_decision_email_screenshot
  FILTER_low_confidence_decision_keep_dana_assets
  FILTER_low_confidence_decision_notify_user
  FILTER_low_confidence_decision_subject_rewrite
  IMPERSONATION_high_confidence_decision_action
  IMPERSONATION_high_confidence_decision_email_screenshot
  IMPERSONATION_high_confidence_decision_keep_dana_assets
  IMPERSONATION_high_confidence_decision_notify_user
  IMPERSONATION_high_confidence_decision_subject_rewrite
  IMPERSONATION_medium_confidence_decision_action
  IMPERSONATION_medium_confidence_decision_email_screenshot
  IMPERSONATION_medium_confidence_decision_keep_dana_assets
  IMPERSONATION_medium_confidence_decision_notify_user
  IMPERSONATION_medium_confidence_decision_subject_rewrite
  IMPERSONATION_low_confidence_decision_action
  IMPERSONATION_low_confidence_decision_email_screenshot
  IMPERSONATION_low_confidence_decision_keep_dana_assets
  IMPERSONATION_low_confidence_decision_notify_user
  IMPERSONATION_low_confidence_decision_subject_rewrite
  MALWARE_dynamic_decision_action
  MALWARE_dynamic_decision_email_screenshot
  MALWARE_dynamic_decision_keep_dana_assets
  MALWARE_dynamic_decision_notify_user
  MALWARE_dynamic_decision_subject_rewrite
  MALWARE_static_decision_action
  MALWARE_static_decision_email_screenshot
  MALWARE_static_decision_keep_dana_assets
  MALWARE_static_decision_notify_user
  MALWARE_static_decision_subject_rewrite
  PHISHING_high_confidence_decision_action
  PHISHING_high_confidence_decision_email_screenshot
  PHISHING_high_confidence_decision_keep_dana_assets
  PHISHING_high_confidence_decision_notify_user
  PHISHING_high_confidence_decision_subject_rewrite
  PHISHING_medium_confidence_decision_action
  PHISHING_medium_confidence_decision_email_screenshot
  PHISHING_medium_confidence_decision_keep_dana_assets
  PHISHING_medium_confidence_decision_notify_user
  PHISHING_medium_confidence_decision_subject_rewrite
  PHISHING_low_confidence_decision_action
  PHISHING_low_confidence_decision_email_screenshot
  PHISHING_low_confidence_decision_keep_dana_assets
  PHISHING_low_confidence_decision_notify_user
  PHISHING_low_confidence_decision_subject_rewrite
  SPAM_high_confidence_decision_action
  SPAM_high_confidence_decision_email_screenshot
  SPAM_high_confidence_decision_keep_dana_assets
  SPAM_high_confidence_decision_notify_user
  SPAM_high_confidence_decision_subject_rewrite
  SPAM_medium_confidence_decision_action
  SPAM_medium_confidence_decision_email_screenshot
  SPAM_medium_confidence_decision_keep_dana_assets
  SPAM_medium_confidence_decision_notify_user
  SPAM_medium_confidence_decision_subject_rewrite
  SPAM_low_confidence_decision_action
  SPAM_low_confidence_decision_email_screenshot
  SPAM_low_confidence_decision_keep_dana_assets
  SPAM_low_confidence_decision_notify_user
  SPAM_low_confidence_decision_subject_rewrite
  VIP_FRAUD_high_confidence_decision_action
  VIP_FRAUD_high_confidence_decision_email_screenshot
  VIP_FRAUD_high_confidence_decision_keep_dana_assets
  VIP_FRAUD_high_confidence_decision_notify_user
  VIP_FRAUD_high_confidence_decision_subject_rewrite
  VIP_FRAUD_medium_confidence_decision_action
  VIP_FRAUD_medium_confidence_decision_email_screenshot
  VIP_FRAUD_medium_confidence_decision_keep_dana_assets
  VIP_FRAUD_medium_confidence_decision_notify_user
  VIP_FRAUD_medium_confidence_decision_subject_rewrite
  VIP_FRAUD_low_confidence_decision_action
  VIP_FRAUD_low_confidence_decision_email_screenshot
  VIP_FRAUD_low_confidence_decision_keep_dana_assets
  VIP_FRAUD_low_confidence_decision_notify_user
  VIP_FRAUD_low_confidence_decision_subject_rewrite
  INTERNAL_EXTORTION_decision_action
  INTERNAL_EXTORTION_decision_email_screenshot
  INTERNAL_EXTORTION_decision_keep_dana_assets
  INTERNAL_EXTORTION_decision_notify_user
  INTERNAL_EXTORTION_decision_subject_rewrite
  INTERNAL_PHISHING_high_confidence_decision_action
  INTERNAL_PHISHING_high_confidence_decision_email_screenshot
  INTERNAL_PHISHING_high_confidence_decision_keep_dana_assets
  INTERNAL_PHISHING_high_confidence_decision_notify_user
  INTERNAL_PHISHING_high_confidence_decision_subject_rewrite
  INTERNAL_PHISHING_medium_confidence_decision_action
  INTERNAL_PHISHING_medium_confidence_decision_email_screenshot
  INTERNAL_PHISHING_medium_confidence_decision_keep_dana_assets
  INTERNAL_PHISHING_medium_confidence_decision_notify_user
  INTERNAL_PHISHING_medium_confidence_decision_subject_rewrite
  INTERNAL_PHISHING_low_confidence_decision_action
  INTERNAL_PHISHING_low_confidence_decision_email_screenshot
  INTERNAL_PHISHING_low_confidence_decision_keep_dana_assets
  INTERNAL_PHISHING_low_confidence_decision_notify_user
  INTERNAL_PHISHING_low_confidence_decision_subject_rewrite
  WHITELIST_decision_action
  SIMULATION_decision_action
  ```
</Accordion>

Available suffixes to the parameters for inbound email defense:

| General parameter suffix | Function                                                                                                                    | Values                                                                                                                           |
| :----------------------- | :-------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------- |
| `_action`                | Decides what should happen with the email                                                                                   | `QUARANTINE`, `DROP`, `DELIVER` or `UNDECIDED`  `UNDECIDED` will result in a `DELIVER` if no other rule specifies another action |
| `_email_screenshot`      | Enables or disables [email content preview](/latest/data-retention-previews#change-email-previews) as a static image        | `true` or `false`                                                                                                                |
| `_keep_dana_assets`      | Enables or disables [storing Sandbox screenshots](/latest/xorlab-sandbox#show-screenshots-for-benign-attachments)           | `true` or `false`                                                                                                                |
| `_notfiy_user`           | Sends the recipient a notification that an incoming email has been quarantined                                              | `true` or `false`                                                                                                                |
| `_subject_rewrite`       | Prepends a specified text to the email when delivered. Usually used in conjunction with the `DELIVER` or `UNDECIDED` action | text string                                                                                                                      |

Those rule parameters can be adjusted per verdict and confidence. For example, the following configuration activates quarantining for high-confidence phishing, but delivers medium-confidence phishing with a subject rewrite:

```shell local.properties theme={null}
# Quarantine high-confidence phishing emails
PHISHING_high_confidence_decision_action=QUARANTINE
# Do not send a quarantine notification
PHISHING_high_confidence_decision_notify_user=false
# Do not do a subject rewrite
PHISHING_high_confidence_decision_subject_rewrite=
 
# Deliver medium-phishing confidence emails (if no other verdict has another decision)
# Specifying DELIVER would force-deliver this email even if another verdict also applies
PHISHING_medium_confidence_decision_action=UNDECIDED
# Do not send a quarantine notification
PHISHING_medium_confidence_decision_notify_user=false
# Do a subject rewrite with [SPAM]
PHISHING_medium_confidence_decision_subject_rewrite=[SPAM]
```

## Parameters for reported emails

<Accordion title="Available parameters">
  ```shell theme={null}
  REPORTED_enable_filter_decision_state
  REPORTED_enable_receipt_acknowledgement_state
  REPORTED_enable_receipt_acknowledgement_template
  REPORTED_BEC_decision_action
  REPORTED_BEC_decision_template
  REPORTED_BENIGN_early_decision_action
  REPORTED_BENIGN_early_decision_template
  REPORTED_EXTORTION_decision_action
  REPORTED_EXTORTION_decision_template
  REPORTED_FILTER_high_confidence_decision_action
  REPORTED_FILTER_high_confidence_decision_template
  REPORTED_FILTER_medium_confidence_decision_action
  REPORTED_FILTER_medium_confidence_decision_template
  REPORTED_FILTER_low_confidence_decision_action
  REPORTED_FILTER_low_confidence_decision_template
  REPORTED_BLACKLIST_decision_action
  REPORTED_BLACKLIST_decision_template
  REPORTED_IMPERSONATION_high_confidence_decision_action
  REPORTED_IMPERSONATION_high_confidence_decision_template
  REPORTED_IMPERSONATION_medium_confidence_decision_action
  REPORTED_IMPERSONATION_medium_confidence_decision_template
  REPORTED_IMPERSONATION_low_confidence_decision_action
  REPORTED_IMPERSONATION_low_confidence_decision_template
  REPORTED_INTERNALLY_FORWARDED_decision_action
  REPORTED_INTERNALLY_FORWARDED_decision_template
  REPORTED_MALWARE_dynamic_decision_action
  REPORTED_MALWARE_dynamic_decision_template
  REPORTED_MALWARE_static_decision_action
  REPORTED_MALWARE_static_decision_template
  REPORTED_PHISHING_high_confidence_decision_action
  REPORTED_PHISHING_high_confidence_decision_template
  REPORTED_PHISHING_low_confidence_decision_action
  REPORTED_PHISHING_low_confidence_decision_template
  REPORTED_PHISHING_medium_confidence_decision_action
  REPORTED_PHISHING_medium_confidence_decision_template
  REPORTED_SIMULATION_decision_action
  REPORTED_SIMULATION_decision_template
  REPORTED_NOT_JUNK_decision_action
  REPORTED_NOT_JUNK_decision_template
  REPORTED_SPAM_high_confidence_decision_action
  REPORTED_SPAM_high_confidence_decision_template
  REPORTED_SPAM_low_confidence_decision_action
  REPORTED_SPAM_low_confidence_decision_template
  REPORTED_SPAM_medium_confidence_decision_action
  REPORTED_SPAM_medium_confidence_decision_template
  REPORTED_VIP_FRAUD_high_confidence_decision_action
  REPORTED_VIP_FRAUD_high_confidence_decision_template
  REPORTED_VIP_FRAUD_medium_confidence_decision_action
  REPORTED_VIP_FRAUD_medium_confidence_decision_template
  REPORTED_VIP_FRAUD_low_confidence_decision_action
  REPORTED_VIP_FRAUD_low_confidence_decision_template
  REPORTED_WHITELIST_decision_action
  REPORTED_WHITELIST_decision_template
  ```
</Accordion>

The parameters for the handling of reported emails allow you to specify when a case should be handled automatically and with which feedback email:

| General parameter suffix | Function                                                                                                                                                                                                                                                                                                                                                                                           | Values                                                                                                                                                                    |
| :----------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `_action`                | Specifies whether the case should be kept open or automatically closed                                                                                                                                                                                                                                                                                                                             | `QUARANTINE` (keep case open), `DROP` (auto-handle case) and `UNDECIDED`<br /><br />`UNDECIDED` will result in `QUARANTINE` if no other rule specifies a different action |
| `_template`              | Specifies which feedback template should be sent back to the reporter. If the case is auto-handled, this feedback template will be automatically sent. If the case is kept open, this feedback template will be pre-selected in the web interface, but not sent. If this parameter is left empty, no feedback template is sent. All available templates can be seen under `shared/email_templates` | Name of a template (for a list of all available templates, please refer to [Email Notification Templates](/latest/email-template-overview))                               |

The following example shows how to auto-handle high-confidence phishing, but keep medium-confidence phishing cases open:

```shell local.properties theme={null}
# Auto-handle emails classified as high-confidence phishing
REPORTED_PHISHING_high_confidence_decision_action=DROP
# Send back the phishing template
REPORTED_PHISHING_high_confidence_decision_template=PHISHING

# Keep case open if the email is classified as medium-confidence phishing
REPORTED_PHISHING_medium_confidence_decision_action=UNDECIDED
# Preselect the phishing template, but don't send it
REPORTED_PHISHING_medium_confidence_decision_template=PHISHING
```

Benign emails must fulfill additional requirements in order to be auto-handled based on the benign verdict (i.e., with `REPORTED_BENIGN_early_decision_action=DROP`). This should ensure that no malicious email is accidentally auto-handled as benign. Therefore, reported emails may be marked as benign, but not auto-handled.

The most important requirements for auto-handling benign emails are:

* All links must have a local reputation above 0.
* Email must be internal or the sender must have at least medium trust.
* No suspicious files attached (e.g., no HTML files).
* No high spam or risk score.
* No cloud storage links.

#### Disable acknowledgment emails

Normally, acknowledgment emails are disabled via the *Actions* configuration screen. In special cases, you can configure the following in `activeguard/core/rule_sets/90_local/params/local.properties`:

```shell theme={null}
# Disable acknowledgment emails. Set to ACTIVE to enable it again
REPORTED_enable_receipt_acknowledgement_state=DISABLED
```

The email template used for the acknowledgment email can be configured in the following way (`ACKNOWLEDGE_RECEIPT` is the default):

```shell theme={null}
# Specify the template used for acknowledgment emails
REPORTED_enable_receipt_acknowledgement_template=ACKNOWLEDGE_RECEIPT
```

## Multi-Tenancy

The `local.properties` file used throughout this page lives in `90_local` and therefore applies to **all** tenants.

To set a parameter for a single tenant only, use a `tenant.properties` file in that tenant's rule set instead of `local.properties`. See [Manage Tenant Rules](/latest/multi-tenancy-rules#tenant-specific-parameters) for the setup.

To switch a tenant to a completely different set of parameters, reference a different [rule profile](/latest/rule-profiles) for that tenant.
