Tag Management
Last updated
Last updated
Tags are conditions that are used by Add-in to identify whether an e-mail is safe or not. The outlook add-in checks all enabled tags. Founded tags or violations are listed in the Tags column of the logs. By examining the reported tags, a security administrator can decide to report malicious e-mail or escalate to different users for further checks.
Under the Tags menu, you can enable which checks will be executed by Add-in and define conditions.
Full list of tags are summarized below:
System Tags:
Link Mismatch: Specifies that monitored link or text in the mail body is not the same as the redirected link.
Name MailAddress Mismatch: Specifies that the sender name and surname are not compatible with the sender mail address.
HTML: Specifies that the mail is in HTML format.
Attachment: Specifies that the mail has an attachment/attachments.
Picture: Specifies that the mail contains a picture/pictures.
Link: Specifies that the body of the mail contains a link/links.
Link Sender Domain Mismatch: Specifies that the domain of sender address is not compatible with domains in the mail body.
Link in Picture: Specifies that picture in the body of the mail contains a link.
From Reply-To Mismatch: Specifies that the sender mail address is not compatible with the ReplyTo mail address.
To CC Empty: Specifies that To and CC fields of mail are empty.
SPF Fail: Specifies that the SPF value in the mail header information is Fail.
Link in File: Specifies that Files at the attachment have a link/links.
Recipient Mailbox Address Mismatch: Specifies that the recipient mail address is not compatible with the mailbox mail address.
To From Same: Specifies that the recipient mail address is the same as the sender mail address.
DKIM Fail: Specifies that the DKIM value in the mail header information is Fail.
DMARC Fail: Specifies that the DMARC value in the mail header information is Fail.
Suspicious Domain Category: Specifies the categories of domains in the mail body to be tagged as suspicious.
Malicious Domain Category: Specifies the categories of domains in the mail body to be tagged as malicious.
Suspicious IP: Specifies that the e-mail’s sender IP address is found suspicious due to the result of VirusTotal.
Suspicious Hash: Specifies that the Hashes of files at the attachment are found suspicious as a result of VirusTotal.
Suspicious Link: Specifies that the links in the body of mail are found suspicious as a result of VirusTotal.
Suspicious Domain: Specifies that the domains in the mail are found suspicious as a result of VirusTotal.
Matched from Shared Intelligence: Specifies that IoC information in the reported e-mail is matched with shared Intelligence.
Matched from Phishing Feed: Specifies that IoC information in the reported e-mail is matched with Phishing Feed.
Custom Tags:
Suspicious Words: Specifies the words to be tagged in the body of the e-mail.
First Time Seen: Specifies that the recipient received a mail from the sender address for the first time in a defined period.
Suspicious Command in File: Specifies the commands to be tagged in the files in the attachment.
IP Out of Range: Specifies that Sender IP Address is out of whitelisted IP ranges.
Suspicious TLD: Specifies the TLD value(Generic&Country-Based) to be tagged in the domains in the body of the e-mail.
Suspicious File: Specifies the file extensions to be tagged at the attachment of the e-mail.
Suspicious Extension: Specifies the TLD value(Generic&Country-Based) to be tagged in the sender domain address of the e-mail.
Suspicious Character in Domain: Specifies the character to be tagged in the e-mail’s sender domain address.
Suspicious Character in From/To : Specifies the character to be tagged in the e-mail’s sender and e-mail's receiver.
Newly Registered Domain: Specifies that the ages of domains in the e-mail are below the defined age.