Spam and phishing protection settings
How Zomail spam and phishing protection works for users and admins: External tag, link checks, Report phishing, quarantine, ZAP, block lists and DMARC reports.
On this page
Every message reaching Zomail is checked for spam and viruses, and phishing protection adds warnings, link checks and an admin response kit on top. This page explains what users see and what administrators can change.
For users: what you see in your inbox
The External tag. Mail from outside your organisation shows an External tag next to the subject. The first message from someone new also says "You haven't received mail from this sender before." A message "from your director" that carries the External tag is a classic sign of fraud. Some organisations also add a prefix such as [EXTERNAL] to the subject, so Outlook and phones show it too.
Link warnings. When your organisation checks links (on by default), each link you click in webmail is checked at that moment:
- A safe link opens normally.
- A suspicious link (for example, the text shows one address but the link goes elsewhere, or it points at a bare IP address) opens a warning page. Read the reason. Choose Continue to the site only if you trust the sender, and never type a password or payment details there. Otherwise choose Back to the message.
- A dangerous link (on a known phishing or malware list) is blocked. Don't open it. Open anyway appears only if your organisation allows it, and your administrators can see that you used it.
Banners in the message. You may see warnings such as "Your organisation has blocked the sender …" or that the sender's name looks like a protected name but the mail came from a different address.
For users: Report spam or Report phishing?
They do different jobs, so pick the right one.
| Use | When | What happens |
|---|---|---|
| Report spam | Unwanted advertising or bulk mail | The message goes to Junk and the spam filter learns from it |
| Report phishing (in the More menu) | Requests for passwords or payments, fake invoices, someone pretending to be a colleague | The message goes to Junk and your administrators are alerted; they can remove it from everyone's mailbox |
If something good landed in Junk, open it and click Not spam. To manage individual senders, go to Settings → Blocked and trusted senders, where you can block or trust an address or a whole domain. You can also choose "Always block this sender" or Never send this sender to spam from a message.
For users: quarantine and removed messages
Quarantine. If your organisation turns on the quarantine, mail that is almost certainly spam or phishing is held on the server instead of being delivered, even to Junk. It is kept for 30 days by default. To see it, open Junk → See quarantined mail, or use the link in the daily summary e-mail. For spam, click Release to Inbox. For phishing or policy holds, click Request release and an administrator decides. Outlook and phone mail apps can't see the quarantine.
Removed after delivery (ZAP). If a message turns out to be dangerous after it arrived (a link gets listed as phishing, the organisation blocks the sender, or several colleagues report it), Zomail moves it out of your Inbox to Junk within 48 hours of delivery. A banner in the message explains why. If you're sure it is safe, click Not spam and it won't be moved again.
For admins: the anti-phishing policy
Open the admin console at https://mail.zomail.io/admin, open your organisation's page and go to Mail security → Anti-phishing policy. Owners and administrators can change it; helpdesk users can view it. Changes take effect within about a minute after Save policy.
| Setting | Default | What it does |
|---|---|---|
| Tag mail from outside the organisation as "External" | On | Shows the External tag and the first-contact notice |
| Also add a prefix to the subject of external mail | Off, [EXTERNAL] | Writes the prefix into the subject at delivery, so IMAP apps see it. It breaks the DKIM signature of those messages, so read the notes on the page first |
| Check links when people click them | On | Click-time link checks with warning and block pages |
| Let people open a blocked link anyway | On | Turn off to remove Open anyway from block pages |
| Remove dangerous mail from the Inbox after delivery (ZAP) | Off | Moves mail delivered in the last 48 hours that is later found dangerous |
| Quarantine almost-certain spam and phishing | Off | Holds known-phishing and very high-scoring spam on the server |
| Send a daily summary to people with quarantined mail | On | Morning e-mail listing newly held mail |
| Spam score threshold for quarantine | 10 (range 5–15) | Score at or above which spam is quarantined |
| Detection strictness | Standard | Strict catches more lookalikes and reordered names, with more false alarms |
| When an outsider uses a colleague's name | Warn in the message only | Or move to Junk, or quarantine |
| When the sender's domain looks like ours or a partner's | Warn in the message only | Catches lookalikes such as example-co.com and homograph tricks |
| When mail forges a domain (fails DMARC) | Warn in the message only | Or move to Junk, or quarantine |
Protected names are people who get impersonated: the director, the chief accountant. Add a display name and, optionally, their real outside address (for example the chair's personal Gmail) so genuine mail from it is not flagged. Colleagues inside the organisation are protected already. Protected domains are partners, banks and suppliers whose domains get faked.
Allow and block lists apply to the whole organisation. A blocked sender always goes to Junk for everyone. An allowed sender skips Junk unless the mail fails DMARC. You can't allow your own domain. The default limits are 200 names, 200 domains and 2,000 senders.
For admins: handling reported phishing
- Open Mail security → Reported phishing. Each report shows who reported it, the sender, the subject and an automatic assessment.
- Open a report to see the headers, the SPF, DKIM and DMARC results, the links (as text only) and the attachment names. Viewing the full body is possible, and each view is logged.
- If it is harmless, click Dismiss (not phishing).
- If it is phishing, use Remove from every mailbox: optionally include messages from the same sender with the same subject in the last few days, and tick Block this sender for the whole organisation. Click Count matching messages (dry run). Nothing is removed yet.
- Check the count, confirm with your password or 2-step code, and remove. Messages move to the quarantine and can be restored to their original folders if you made a mistake.
Quarantine review: Mail security → Quarantine lists held mail and release requests. Release a message, release it and allow the sender or domain, or delete it. Unhandled mail expires after 30 days. Blocked and warned links shows recent risky clicks. If someone continued past a block page, ask whether they typed a password, and reset it if so.
For admins: DMARC reports
Admin → DMARC reports shows, for the last 30 days, who sends mail as your domain, how much passes DMARC, and recommendations. Fix legitimate senders that fail (add them to SPF, or turn on DKIM at that service) before you tighten your DMARC policy. Unknown sources are likely spoofing. See getting started for the DMARC record.
Related: admin basics and the FAQ. If a phishing incident is under way and you need help, contact Zomail support.
FAQ
Why is mail from my own colleague marked External?
It was probably sent from outside your organisation, for example a personal address, or through a service that isn't authorised for your domain. Check the sender address carefully.
Can Zomail staff read our reported or quarantined messages?
No. Reported phishing, the quarantine, clicked links and ZAP pages are visible only to your organisation's owners and administrators.
Does the [EXTERNAL] prefix have downsides?
Yes. Because it changes the subject, it breaks the original DKIM signature of those messages. Most organisations rely on the External tag instead.