Reported phishing
People report phishing from their mail app; administrators remove it from everybody, block its sender or give it back, and the server can take it back on its own.
When one person spots a phishing message, everybody else who got it should lose it too, and the administrators should hear about it. Nixt Server does both. People report a message from their mail app. Every report joins one list, under Protection › Reported on the console, with who reported it, what the message arrived with and how many people have it. From there an administrator removes it from everybody, blocks its sender or gives it back. An organisation can also have the server take a reported message back on its own.
The examples use the vsx shell function from the Quick start.
How people report a message
A person reports a message by marking it as phishing in their mail app. The app sets the keyword $Phishing on the message, over IMAP or JMAP. The server lists $Phishing among the flags a mailbox takes (FLAGS and PERMANENTFLAGS), so an IMAP app can see that it is understood here. Setting the keyword is the report: moving the message to Junk as well is up to the app.
- Each person counts once per message, however often they report it.
- A report is about the message, not one person’s copy. Copies are matched by their
Message-ID, or by their content when there is none, so every copy delivered to the organisation is found. The server finds them without reading anybody’s mail. - The first report of a message tells the administrators, by the
reported-phishingalert. An organisation has it unless it saved its alerts without it.
A later verdict
A message can turn out to be phishing after it arrived: a link in it is listed by a blocklist an hour later, or the virus scanner’s next update recognises an attachment. For 48 hours after delivery, the server asks again about each message from outside that links somewhere or carries attachments:
- Every ten minutes, it checks the message’s links against the filter’s own domain blocklists, each linked host at most once an hour.
- When ClamAV’s signatures change, it scans the attachments again.
A host that was clear when the message arrived and is listed later, or an attachment the scanner now recognises, is reported just as a person’s report is, with Found later saying what was found. A host that was already listed when the message arrived was the filter’s to weigh at the time, so it is not reported.
The Reported list
On the console, Protection › Reported lists what was reported, newest first. For each message:
| Shown | What it says |
|---|---|
| Reported by | Who reported it and when. Nobody: the server found it for a later verdict. |
| Found later | What a later verdict found. |
| Sent by | The envelope sender, from the message’s trace. |
| Proved it’s from | The From: domain DMARC proved, when it passed. |
| Authentication | The server’s own authentication results for the message when it arrived. |
| Filter’s verdict | What the filter decided at delivery, with its score. |
| Who has it | How many of the organisation’s people hold a copy, how many have not opened it, and in which domains. |
| Its trace | A link to the message’s trace. |
Nothing the message says is shown: not its subject, its From: line or its text.
Each message is in one of four states: Waiting for you, Taken back (by the server), Removed from everybody or Not phishing.
From the command line:
vsx admin reported list
5f0e8a1c2b3d4e5f60718293a4b5c6d7 taken-back reported by 3: ada@example.com, bo@example.com
from bounce@phish.example; spf=pass; dmarc=fail header.from=bank.example
40 people have it, 31 not opened yet
The long number at the start of each report is its id, which the commands below take.
Acting on a report
| Console | Command | What it does |
|---|---|---|
| Remove from everybody | reported remove <id> | Takes every copy out of every mailbox, opened or not, in quarantine or not. Anybody who had opened theirs is told in their inbox, under the subject A message you opened was removed as phishing. |
| Block the sender | reported block <id> | Adds the envelope sender to the organisation’s blocked senders. |
| Not phishing | reported dismiss <id> | Gives back every copy the server took back into quarantine. The reporters’ own copies come back from Junk without the keyword, and the reporters are told in their inbox, under the subject The message you reported is not phishing. |
Each copy removed or given back is its own line in the audit log and a step in the message’s trace. A message marked Not phishing stays that way: later reports of it take nothing back.
Blocking is refused when the sender is not known (a bounce has none, and an old message’s trace may be past its keep), when the sender is one of the organisation’s own addresses, and when it is on the organisation’s allowed senders. A sender already blocked is left as it is.
Taking reported phishing back automatically
An organisation can have the server act without waiting for an administrator. On the console, the setting is Taking back reported phishing under Settings:
| Choice | What happens |
|---|---|
| Off (the default) | Reported messages wait for an administrator. |
| On | Unread copies go into quarantine as soon as enough people report the message, or a later verdict finds it. |
With it on, After how many different people’s reports sets the number: three unless you change it, and never fewer than two, so one person cannot take a message away from everybody on their own.
When the server takes a message back:
- Every copy nobody has opened goes into its holder’s quarantine, where an administrator can release it.
- Anybody who had already opened theirs keeps it and is warned in their inbox, under the subject A message you opened was reported as phishing. The people who reported it are not told again.
- The administrators are told by the
reported-phishingalert. - Each copy taken is a line in the audit log, under the role
protectionand the verbtake-back, and ataken-backstep in the message’s trace. The trace search then finds the copy as quarantined.
From the command line:
vsx admin org phishing-takeback on --reports 3
vsx admin org phishing-takeback off
These are the runtime settings protection.auto_takeback (on or off) and protection.takeback_reports (a number, 2 or more), which you can also set with settings set.
Who can do what
| Role | Can |
|---|---|
| Organisation administrator | Everything on this page. |
| Domain administrator | See the reports that reached their domains’ people, and remove or give back the copies in their domains. Blocking a sender changes the organisation’s list, so it is for the organisation’s administrators. |
| Auditor | See the list. |
| Helpdesk | Nothing here. |
Over the API
| Route | What it does |
|---|---|
GET /api/v1/tenants/{tenant}/reported | The list, 50 to a page unless limit says otherwise (200 at most); next, when there is more, is after for the next page. |
POST /api/v1/tenants/{tenant}/reported/{id}/remove | Remove from everybody. Answers each copy found, how many were removed and how many people are told. |
POST /api/v1/tenants/{tenant}/reported/{id}/dismiss | Not phishing. Answers how many copies were returned and how many people are told. |
POST /api/v1/tenants/{tenant}/reported/{id}/block | Block the sender. Answers the sender blocked, whether it was added, and the organisation’s list as it stands. |
To take a message out of every mailbox without anybody having reported it, use message purge.
Something unclear or out of date on this page? Tell us.