Reported phishing

People report phishing from their mail app; administrators remove it from everybody, block its sender or give it back, and the server can take it back on its own.

When one person spots a phishing message, everybody else who got it should lose it too, and the administrators should hear about it. Nixt Server does both. People report a message from their mail app. Every report joins one list, under Protection › Reported on the console, with who reported it, what the message arrived with and how many people have it. From there an administrator removes it from everybody, blocks its sender or gives it back. An organisation can also have the server take a reported message back on its own.

The examples use the vsx shell function from the Quick start.

How people report a message

A person reports a message by marking it as phishing in their mail app. The app sets the keyword $Phishing on the message, over IMAP or JMAP. The server lists $Phishing among the flags a mailbox takes (FLAGS and PERMANENTFLAGS), so an IMAP app can see that it is understood here. Setting the keyword is the report: moving the message to Junk as well is up to the app.

  • Each person counts once per message, however often they report it.
  • A report is about the message, not one person’s copy. Copies are matched by their Message-ID, or by their content when there is none, so every copy delivered to the organisation is found. The server finds them without reading anybody’s mail.
  • The first report of a message tells the administrators, by the reported-phishing alert. An organisation has it unless it saved its alerts without it.

A later verdict

A message can turn out to be phishing after it arrived: a link in it is listed by a blocklist an hour later, or the virus scanner’s next update recognises an attachment. For 48 hours after delivery, the server asks again about each message from outside that links somewhere or carries attachments:

  • Every ten minutes, it checks the message’s links against the filter’s own domain blocklists, each linked host at most once an hour.
  • When ClamAV’s signatures change, it scans the attachments again.

A host that was clear when the message arrived and is listed later, or an attachment the scanner now recognises, is reported just as a person’s report is, with Found later saying what was found. A host that was already listed when the message arrived was the filter’s to weigh at the time, so it is not reported.

The Reported list

On the console, Protection › Reported lists what was reported, newest first. For each message:

ShownWhat it says
Reported byWho reported it and when. Nobody: the server found it for a later verdict.
Found laterWhat a later verdict found.
Sent byThe envelope sender, from the message’s trace.
Proved it’s fromThe From: domain DMARC proved, when it passed.
AuthenticationThe server’s own authentication results for the message when it arrived.
Filter’s verdictWhat the filter decided at delivery, with its score.
Who has itHow many of the organisation’s people hold a copy, how many have not opened it, and in which domains.
Its traceA link to the message’s trace.

Nothing the message says is shown: not its subject, its From: line or its text.

Each message is in one of four states: Waiting for you, Taken back (by the server), Removed from everybody or Not phishing.

From the command line:

vsx admin reported list
5f0e8a1c2b3d4e5f60718293a4b5c6d7  taken-back  reported by 3: ada@example.com, bo@example.com
    from bounce@phish.example; spf=pass; dmarc=fail header.from=bank.example
    40 people have it, 31 not opened yet

The long number at the start of each report is its id, which the commands below take.

Acting on a report

ConsoleCommandWhat it does
Remove from everybodyreported remove <id>Takes every copy out of every mailbox, opened or not, in quarantine or not. Anybody who had opened theirs is told in their inbox, under the subject A message you opened was removed as phishing.
Block the senderreported block <id>Adds the envelope sender to the organisation’s blocked senders.
Not phishingreported dismiss <id>Gives back every copy the server took back into quarantine. The reporters’ own copies come back from Junk without the keyword, and the reporters are told in their inbox, under the subject The message you reported is not phishing.

Each copy removed or given back is its own line in the audit log and a step in the message’s trace. A message marked Not phishing stays that way: later reports of it take nothing back.

Blocking is refused when the sender is not known (a bounce has none, and an old message’s trace may be past its keep), when the sender is one of the organisation’s own addresses, and when it is on the organisation’s allowed senders. A sender already blocked is left as it is.

Taking reported phishing back automatically

An organisation can have the server act without waiting for an administrator. On the console, the setting is Taking back reported phishing under Settings:

ChoiceWhat happens
Off (the default)Reported messages wait for an administrator.
OnUnread copies go into quarantine as soon as enough people report the message, or a later verdict finds it.

With it on, After how many different people’s reports sets the number: three unless you change it, and never fewer than two, so one person cannot take a message away from everybody on their own.

When the server takes a message back:

  • Every copy nobody has opened goes into its holder’s quarantine, where an administrator can release it.
  • Anybody who had already opened theirs keeps it and is warned in their inbox, under the subject A message you opened was reported as phishing. The people who reported it are not told again.
  • The administrators are told by the reported-phishing alert.
  • Each copy taken is a line in the audit log, under the role protection and the verb take-back, and a taken-back step in the message’s trace. The trace search then finds the copy as quarantined.

From the command line:

vsx admin org phishing-takeback on --reports 3
vsx admin org phishing-takeback off

These are the runtime settings protection.auto_takeback (on or off) and protection.takeback_reports (a number, 2 or more), which you can also set with settings set.

Who can do what

RoleCan
Organisation administratorEverything on this page.
Domain administratorSee the reports that reached their domains’ people, and remove or give back the copies in their domains. Blocking a sender changes the organisation’s list, so it is for the organisation’s administrators.
AuditorSee the list.
HelpdeskNothing here.

Over the API

RouteWhat it does
GET /api/v1/tenants/{tenant}/reportedThe list, 50 to a page unless limit says otherwise (200 at most); next, when there is more, is after for the next page.
POST /api/v1/tenants/{tenant}/reported/{id}/removeRemove from everybody. Answers each copy found, how many were removed and how many people are told.
POST /api/v1/tenants/{tenant}/reported/{id}/dismissNot phishing. Answers how many copies were returned and how many people are told.
POST /api/v1/tenants/{tenant}/reported/{id}/blockBlock the sender. Answers the sender blocked, whether it was added, and the organisation’s list as it stands.

To take a message out of every mailbox without anybody having reported it, use message purge.

Something unclear or out of date on this page? Tell us.