Spam and phishing protection settings

How Zomail spam and phishing protection works for users and admins: External tag, link checks, Report phishing, quarantine, ZAP, block lists and DMARC reports.

On this page
  1. For users: what you see in your inbox
  2. For users: Report spam or Report phishing?
  3. For users: quarantine and removed messages
  4. For admins: the anti-phishing policy
  5. For admins: handling reported phishing
  6. For admins: DMARC reports
  7. FAQ

Every message reaching Zomail is checked for spam and viruses, and phishing protection adds warnings, link checks and an admin response kit on top. This page explains what users see and what administrators can change.

For users: what you see in your inbox

The External tag. Mail from outside your organisation shows an External tag next to the subject. The first message from someone new also says "You haven't received mail from this sender before." A message "from your director" that carries the External tag is a classic sign of fraud. Some organisations also add a prefix such as [EXTERNAL] to the subject, so Outlook and phones show it too.

Link warnings. When your organisation checks links (on by default), each link you click in webmail is checked at that moment:

  • A safe link opens normally.
  • A suspicious link (for example, the text shows one address but the link goes elsewhere, or it points at a bare IP address) opens a warning page. Read the reason. Choose Continue to the site only if you trust the sender, and never type a password or payment details there. Otherwise choose Back to the message.
  • A dangerous link (on a known phishing or malware list) is blocked. Don't open it. Open anyway appears only if your organisation allows it, and your administrators can see that you used it.

Banners in the message. You may see warnings such as "Your organisation has blocked the sender …" or that the sender's name looks like a protected name but the mail came from a different address.

For users: Report spam or Report phishing?

They do different jobs, so pick the right one.

UseWhenWhat happens
Report spamUnwanted advertising or bulk mailThe message goes to Junk and the spam filter learns from it
Report phishing (in the More menu)Requests for passwords or payments, fake invoices, someone pretending to be a colleagueThe message goes to Junk and your administrators are alerted; they can remove it from everyone's mailbox

If something good landed in Junk, open it and click Not spam. To manage individual senders, go to Settings → Blocked and trusted senders, where you can block or trust an address or a whole domain. You can also choose "Always block this sender" or Never send this sender to spam from a message.

For users: quarantine and removed messages

Quarantine. If your organisation turns on the quarantine, mail that is almost certainly spam or phishing is held on the server instead of being delivered, even to Junk. It is kept for 30 days by default. To see it, open Junk → See quarantined mail, or use the link in the daily summary e-mail. For spam, click Release to Inbox. For phishing or policy holds, click Request release and an administrator decides. Outlook and phone mail apps can't see the quarantine.

Removed after delivery (ZAP). If a message turns out to be dangerous after it arrived (a link gets listed as phishing, the organisation blocks the sender, or several colleagues report it), Zomail moves it out of your Inbox to Junk within 48 hours of delivery. A banner in the message explains why. If you're sure it is safe, click Not spam and it won't be moved again.

For admins: the anti-phishing policy

Open the admin console at https://mail.zomail.io/admin, open your organisation's page and go to Mail security → Anti-phishing policy. Owners and administrators can change it; helpdesk users can view it. Changes take effect within about a minute after Save policy.

SettingDefaultWhat it does
Tag mail from outside the organisation as "External"OnShows the External tag and the first-contact notice
Also add a prefix to the subject of external mailOff, [EXTERNAL]Writes the prefix into the subject at delivery, so IMAP apps see it. It breaks the DKIM signature of those messages, so read the notes on the page first
Check links when people click themOnClick-time link checks with warning and block pages
Let people open a blocked link anywayOnTurn off to remove Open anyway from block pages
Remove dangerous mail from the Inbox after delivery (ZAP)OffMoves mail delivered in the last 48 hours that is later found dangerous
Quarantine almost-certain spam and phishingOffHolds known-phishing and very high-scoring spam on the server
Send a daily summary to people with quarantined mailOnMorning e-mail listing newly held mail
Spam score threshold for quarantine10 (range 5–15)Score at or above which spam is quarantined
Detection strictnessStandardStrict catches more lookalikes and reordered names, with more false alarms
When an outsider uses a colleague's nameWarn in the message onlyOr move to Junk, or quarantine
When the sender's domain looks like ours or a partner'sWarn in the message onlyCatches lookalikes such as example-co.com and homograph tricks
When mail forges a domain (fails DMARC)Warn in the message onlyOr move to Junk, or quarantine

Protected names are people who get impersonated: the director, the chief accountant. Add a display name and, optionally, their real outside address (for example the chair's personal Gmail) so genuine mail from it is not flagged. Colleagues inside the organisation are protected already. Protected domains are partners, banks and suppliers whose domains get faked.

Allow and block lists apply to the whole organisation. A blocked sender always goes to Junk for everyone. An allowed sender skips Junk unless the mail fails DMARC. You can't allow your own domain. The default limits are 200 names, 200 domains and 2,000 senders.

For admins: handling reported phishing

  1. Open Mail security → Reported phishing. Each report shows who reported it, the sender, the subject and an automatic assessment.
  2. Open a report to see the headers, the SPF, DKIM and DMARC results, the links (as text only) and the attachment names. Viewing the full body is possible, and each view is logged.
  3. If it is harmless, click Dismiss (not phishing).
  4. If it is phishing, use Remove from every mailbox: optionally include messages from the same sender with the same subject in the last few days, and tick Block this sender for the whole organisation. Click Count matching messages (dry run). Nothing is removed yet.
  5. Check the count, confirm with your password or 2-step code, and remove. Messages move to the quarantine and can be restored to their original folders if you made a mistake.

Quarantine review: Mail security → Quarantine lists held mail and release requests. Release a message, release it and allow the sender or domain, or delete it. Unhandled mail expires after 30 days. Blocked and warned links shows recent risky clicks. If someone continued past a block page, ask whether they typed a password, and reset it if so.

For admins: DMARC reports

Admin → DMARC reports shows, for the last 30 days, who sends mail as your domain, how much passes DMARC, and recommendations. Fix legitimate senders that fail (add them to SPF, or turn on DKIM at that service) before you tighten your DMARC policy. Unknown sources are likely spoofing. See getting started for the DMARC record.

Related: admin basics and the FAQ. If a phishing incident is under way and you need help, contact Zomail support.

FAQ

Why is mail from my own colleague marked External?

It was probably sent from outside your organisation, for example a personal address, or through a service that isn't authorised for your domain. Check the sender address carefully.

Can Zomail staff read our reported or quarantined messages?

No. Reported phishing, the quarantine, clicked links and ZAP pages are visible only to your organisation's owners and administrators.

Does the [EXTERNAL] prefix have downsides?

Yes. Because it changes the subject, it breaks the original DKIM signature of those messages. Most organisations rely on the External tag instead.