Reporting false positives and negatives

Prev Next

A false positive is a legitimate message which has been incorrectly classified as spam or phishing.

A false negative is a spam or phishing message which has been incorrectly classified as legitimate.

Feedback provided by the end users on the incorrectly-classified messages helps to improve the accuracy of preventing spam or phishing messages reaching the users mailbox.

The messages that you report must be in RFC822 format as MIME attachments. This preserves the email header information that Email Cloud requires.

Note

Do not send misclassified messages by using the Forward command; this strips them of essential header information.

Trellix cannot investigate emails that are more than 30 days old.

Trellix has set up two email addresses for the end users to report both false positives and false negatives. End users should use these email addresses as follows:

Reporting a misclassified message with Microsoft Outlook or Outlook Express

  1. From the File menu, select New > Mail Message to open a new message window.

  2. Address the message to the appropriate address, provided by your email administrator.

  3. Drag the misclassified message or messages onto the new message window to attach them. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.

  4. Click Send to send the message.

Reporting a misclassified message with Thunderbird

  1. From the File menu, select New > Message to open a new message window.

  2. Address the message to the appropriate address, provided by your email administrator.

  3. Drag the misclassified message or messages onto the new message window to attach them. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.

  4. Click Send to send the message.

Reporting a misclassified message with Eudora

  1. In the message list, select the misclassified message.

  2. From the File menu, select Save As.

  3. In the Save As window, navigate to an appropriate location in which to save the message.

  4. Select the Include Headers checkbox.

  5. Click Save. Repeat step 1 through step 5 for each misclassified message.

  6. From the Message menu, select New Message. A new message window appears.

  7. Address the message to the appropriate address, provided by your email administrator.

  8. From the Message menu, select Attach File.

  9. In the Attach File window, navigate to the location where you saved the misclassified message, then select it.

  10. Click Attach. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.

  11. Click Send to send the message.

Reporting a misclassified message with macOS Mail

  1. In the message list, select the misclassified message.

  2. From the File menu, select Save As.

  3. Save the file in an appropriate location.

  4. From the File menu, select New Message to open a new message window.

  5. Address the message to the appropriate address, provided by your email administrator.

  6. From the File menu, select Attach File.

  7. Navigate to the location where you saved the misclassified message, then select it.

  8. Click Choose File to attach the saved file. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.

  9. Click Send to send the message.