A false positive is a legitimate message which has been incorrectly classified as spam or phishing.
A false negative is a spam or phishing message which has been incorrectly classified as legitimate.
Feedback provided by the end users on the incorrectly-classified messages helps to improve the accuracy of preventing spam or phishing messages reaching the users mailbox.
The messages that you report must be in RFC822 format as MIME attachments. This preserves the email header information that Email Cloud requires.
Note
Do not send misclassified messages by using the Forward command; this strips them of essential header information.
Trellix cannot investigate emails that are more than 30 days old.
Trellix has set up two email addresses for the end users to report both false positives and false negatives. End users should use these email addresses as follows:
False positive—When reporting a false positive (legitimate message that was incorrectly classified as spam or phishing message), forward the message as a MIME attachment to the email address corresponding with your region:
False negative—When reporting a false negative (spam or phishing message that was incorrectly classified as a legitimate message), forward the message as a MIME attachment to the email address corresponding with your region:
Reporting a misclassified message with Microsoft Outlook or Outlook Express
From the File menu, select New > Mail Message to open a new message window.
Address the message to the appropriate address, provided by your email administrator.
Drag the misclassified message or messages onto the new message window to attach them. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.
Click Send to send the message.
Reporting a misclassified message with Thunderbird
From the File menu, select New > Message to open a new message window.
Address the message to the appropriate address, provided by your email administrator.
Drag the misclassified message or messages onto the new message window to attach them. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.
Click Send to send the message.
Reporting a misclassified message with Eudora
In the message list, select the misclassified message.
From the File menu, select Save As.
In the Save As window, navigate to an appropriate location in which to save the message.
Select the Include Headers checkbox.
Click Save. Repeat step 1 through step 5 for each misclassified message.
From the Message menu, select New Message. A new message window appears.
Address the message to the appropriate address, provided by your email administrator.
From the Message menu, select Attach File.
In the Attach File window, navigate to the location where you saved the misclassified message, then select it.
Click Attach. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.
Click Send to send the message.
Reporting a misclassified message with macOS Mail
In the message list, select the misclassified message.
From the File menu, select Save As.
Save the file in an appropriate location.
From the File menu, select New Message to open a new message window.
Address the message to the appropriate address, provided by your email administrator.
From the File menu, select Attach File.
Navigate to the location where you saved the misclassified message, then select it.
Click Choose File to attach the saved file. Although you can attach as many messages as you like, your email server is configured to reject messages that are too large. Be aware of your server's size limit when constructing your message.
Click Send to send the message.