Skip to content

Commit 49693af

Browse files
Maddy-Cloudflaremarciocloudflare
authored andcommitted
[Email Security] Clarify steps (cloudflare#23564)
* [Email Security] Clarify steps * Fix numbered lists * Language change * Clarify step + fix links * Fix numbered list * Add log in step * Update src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-auto-moves.mdx Co-authored-by: marciocloudflare <[email protected]> * Add extra step --------- Co-authored-by: marciocloudflare <[email protected]>
1 parent ae29325 commit 49693af

File tree

10 files changed

+106
-89
lines changed

10 files changed

+106
-89
lines changed

src/content/docs/cloudflare-one/email-security/email-monitoring/search-email.mdx

Lines changed: 30 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -78,15 +78,16 @@ Reclassifying messages allows you to choose the disposition of your messages if
7878

7979
To reclassify a message:
8080

81-
1. On the **Investigation** page, under **Your matching messages**, select the message you want to reclassify.
82-
2. Select the three dots, then select **Reclassify**.
83-
3. Under **New disposition**, select among the following:
84-
* **Malicious**: Traffic invoked multiple phishing verdict triggers, met thresholds for bad behavior, and is associated with active campaigns.
85-
* **Spoof**: Traffic associated with phishing campaigns that is either non-compliant with your email authentication policies (SPF, DKIM, DMARC) or has mismatching Envelope From and `Header From` values.
86-
* **Spam**: Traffic associated with non-malicious, commercial campaigns.
87-
* **Bulk**: Traffic associated with [Graymail](https://en.wikipedia.org/wiki/Graymail_%28email%29), that falls in between the definitions of `SPAM` and `SUSPICIOUS`. For example, a marketing email that intentionally obscures its unsubscribe link.
88-
* **Clean**: Traffic not associated with any phishing campaigns.
89-
4. Select **Save**.
81+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security** and select **Investigation**.
82+
2. On the **Investigation** page, under **Your matching messages**, select the message you want to reclassify.
83+
3. Select the three dots, then select **Reclassify**.
84+
4. Under **New disposition**, select among the following:
85+
- **Malicious**: Traffic invoked multiple phishing verdict triggers, met thresholds for bad behavior, and is associated with active campaigns.
86+
- **Spoof**: Traffic associated with phishing campaigns that is either non-compliant with your email authentication policies (SPF, DKIM, DMARC) or has mismatching Envelope From and `Header From` values.
87+
- **Spam**: Traffic associated with non-malicious, commercial campaigns.
88+
- **Bulk**: Traffic associated with [Graymail](https://en.wikipedia.org/wiki/Graymail_%28email%29), that falls in between the definitions of `SPAM` and `SUSPICIOUS`. For example, a marketing email that intentionally obscures its unsubscribe link.
89+
- **Clean**: Traffic not associated with any phishing campaigns.
90+
5. Select **Save**.
9091

9192
To reclassify messages in bulk, select the messages you want to reclassify > **Action** > **Reclassify**.
9293

@@ -166,48 +167,52 @@ Moving messages allows you to move messages to a specific folder. You can move u
166167

167168
To move messages:
168169

169-
1. On the **Investigation** page, select all the messages you want to move.
170-
2. Select the **Action** dropdown, then select **Move**.
171-
3. Select among one of the following folders:
172-
* **Inbox**: Move messages to the primary email folder.
173-
* **Junk email**: Move messages to the junk or spam folder.
174-
* **Trash**: Move messages to the trash or deleted items email folder.
175-
* **Soft delete (user recoverable)**: Move messages to the user's Deleted Items folder. This option is for Microsoft 365 only.
176-
* **Hard delete (admin recoverable)**: Delete messages from a user's inbox.
177-
4. Select **Save**.
170+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**, and select **Investigation**.
171+
2. On the **Investigation** page, select all the messages you want to move.
172+
3. Select the **Action** dropdown, then select **Move**.
173+
4. Select among one of the following folders:
174+
- **Inbox**: Move messages to the primary email folder.
175+
- **Junk email**: Move messages to the junk or spam folder.
176+
- **Trash**: Move messages to the trash or deleted items email folder.
177+
- **Soft delete (user recoverable)**: Move messages to the user's Deleted Items folder. This option is for Microsoft 365 only.
178+
- **Hard delete (admin recoverable)**: Delete messages from a user's inbox.
179+
5. Select **Save**.
178180

179181
## Find similar emails
180182

181183
Each detection has an Email Detection Fingerprint (EDF) hash that Email Security sends to the Search API to retrieve similar detections.
182184

183185
To find similar detection results:
184186

185-
1. On the **Investigation** page, under **Your matching messages**, search for the **Similar emails** column.
186-
2. Select the number of similar emails. Selecting the number will show you a list of similar emails.
187+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**, and select **Investigation**.
188+
2. On the **Investigation** page, under **Your matching messages**, search for the **Similar emails** column.
189+
3. Select the number of similar emails. Selecting the number will show you a list of similar emails.
187190

188191
## Export messages
189192

190193
With Email Security, you can export messages to a CSV file.
191194

192195
To export messages:
193196

194-
1. On the **Investigation** page, under **Your matching messages**, select **Export to CSV**.
195-
2. Select **Export messages** on the pop-up message. You can export up to 500 messages from the dashboard. To export up to 1,000 matching messages, use the [API](/api/resources/email_security/subresources/investigate/methods/get/).
197+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**, and select **Investigation**.
198+
2. On the **Investigation** page, under **Your matching messages**, select **Export to CSV**.
199+
3. Select **Export messages** on the pop-up message. You can export up to 500 messages from the dashboard. To export up to 1,000 matching messages, use the [API](/api/resources/email_security/subresources/investigate/methods/get/).
196200

197201
## Email status
198202

199203
Email Security allows you to review the status and actions of each email.
200204

201205
To view status and actions for each email:
202206

203-
1. On the **Investigation** page, select the three dots.
204-
2. Selecting the three dots will show you the following options:
207+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**, and select **Investigation**.
208+
2. On the **Investigation** page, select the three dots.
209+
3. Selecting the three dots will show you the following options:
205210
- If the email is quarantined:
206211
- **View details**: Refer to [Email details](/cloudflare-one/email-security/email-monitoring/search-email/#email-details) to learn more.
207212
- **View similar emails**: Find similar emails based on the `value_edf_hash` (Electronic Detection Fingerprint hash).
208213
- **Release**: Email Security will no longer quarantine your chosen messages.
209214
- **Reclassify**: Choose the dispositions of your messages if they are incorrect. Refer to [Reclassify messages](/cloudflare-one/email-security/email-monitoring/search-email/#reclassify-messages) to learn more.
210-
3. If the email is not quarantined:
215+
4. If the email is not quarantined:
211216
- **View details**.
212217
- **View similar emails**.
213218
- **View submission detail**.

src/content/docs/cloudflare-one/email-security/index.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,4 +37,4 @@ Email Security overview displays:
3737
- **Recommendations**: A series of recommendations. For example, you may be recommended to learn how to submit emails for reclassification, create policies, or protect users at risk of [impersonation](/cloudflare-one/email-security/detection-settings/impersonation-registry/)
3838
- **Email Security metrics**: Activity from the last seven days.
3939
- **Recently modified policies** A list of modified policies.
40-
- **Education and resources**: Links to [implementation guides](/cloudflare-one/implementation-guides/), [Email Security changelogs](/cloudflare-one/changelog/email-security/), and [API documentation](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/methods/get/)
40+
- **Education and resources**: Links to [implementation guides](/cloudflare-one/implementation-guides/), [Email Security changelogs](/cloudflare-one/changelog/email-security/), and [API documentation](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/methods/get/)

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api.mdx

Lines changed: 17 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -59,27 +59,33 @@ Your domains are now connected successfully.
5959

6060
To connect new domains:
6161

62-
1. Log in to the [Cloudflare dashboard](https://dash.cloudflare.com/).
63-
2. Select **Zero Trust**.
64-
3. Select **Email security**.
65-
4. Select **Settings**.
66-
5. On the **Domain management** page, select **Add a domain**.
67-
6. Select the domains you want Email Security to scan.
68-
7. Select **Save**.
62+
1. In [Zero Trust](https://one.dash.cloudflare.com/), select **Email Security**.
63+
2. Select **Settings** > **Domain management** > **Domains**, then select **View**.
64+
3. Select **Add a domain**.
65+
4. Select a method for connecting your mail environment to Email Security:
66+
- If you select **MS Graph API**, refer to [Enable Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration).
67+
- If you select BCC/Journaling, choose how to connect your domains:
68+
- If you select **Integrate with MS**, refer to [Enable Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration).
69+
- If you select **Integrate with Google**, refer to [Connect your domains](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/connect-domains/).
70+
- If you select **Manual add**, refer to [Enter domain manually](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/manual-add/#enter-domain-manually).
6971

7072
## Prevent Cloudflare from scanning a domain
7173

7274
If you want to prevent Cloudflare from scanning a domain:
7375

74-
1. On the **Domain management** page, select the domain you do not want to be scanned.
75-
2. Select the three dots > **Stop scanning**.
76+
1. In [Zero Trust](https://one.dash.cloudflare.com/), select **Email Security**.
77+
2. Go to **Settings** > **Domain management** > **Domains**, then select **View**.
78+
3. On the **Domain management** page, select the domain you do not want to be scanned.
79+
4. Select the three dots > **Stop scanning**.
7680

7781
## View an integration
7882

7983
To view the integration for each connected domain:
8084

81-
1. Select a domain.
82-
2. Select the three dots > **View integration**.
85+
1. In [Zero Trust](https://one.dash.cloudflare.com/), select **Email Security**.
86+
2. Go to **Settings** > **Domain management** > **Domains**, then select **View**.
87+
3. Select a domain.
88+
4. Select the three dots > **View integration**.
8389

8490
Once you have set up Email Security to scan through your inbox, Email Security will display detailed information about your inbox. Refer to [Monitor your inbox](/cloudflare-one/email-security/email-monitoring/) to learn more.
8591

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/connect-domains.mdx

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@ sidebar:
77

88
import { GlossaryTooltip } from "~/components"
99

10+
To connect your domains, you will need to [enable your Gmail BCC integration](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/#enable-gmail-bcc-integration). Once you have enabled your Gmail BCC integration, the Cloudflare dashboard will redirect you to the **Set up Email Security** page.
11+
1012
On the **Set up Email Security** page:
1113

1214
1. **Connect domains**: Select at least one domain. Then, select **Continue**.
@@ -26,7 +28,7 @@ Under **Source**, the dashboard will display **Google integration**, along with
2628

2729
To add additional domains:
2830

29-
1. Go to **Settings**.
31+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security** > **Settings**.
3032
2. Select **Connect an integration** > **BCC/Journaling** > **Integrate with Google** > **Authorize**.
3133
3. **Connect domains**: Select the domains you want to add, then select **Next**.
3234
4. (Optional) Select **Add manual domains**: Enter additional domains manually, then select **Next**.

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-auto-moves.mdx

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,9 @@ sidebar:
77

88
If you do not have an integration:
99

10-
1. Go to **Settings** > **Domain management** > **Domains** > select **View**.
11-
2. Select the three dots > Select **Associate an integration**.
12-
3. Select **Connect an integration**. You will then be redirected to a page where you will enable your Google integration.
13-
4. Once you have enabled your Google integration, select **Complete Email Security set up**.
10+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**.
11+
2. Go to **Settings** > **Domain management** > **Domains** > select **View**.
12+
3. Locate your domain, select the three dots > Select **Associate an integration**.
13+
4. Select **Connect an integration**. You will then be redirected to the **Add an integration** page.
14+
5. Select **Google Workspace CASB+EMAIL** > **Select Integration**.
15+
6. Once you select an integration, you can [enable Gmail BCC integration](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/#enable-gmail-bcc-integration).

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration.mdx

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -87,15 +87,16 @@ Enter the email associated with the Google Workspace Administrator account. Your
8787

8888
To verify that the integration has been successful:
8989

90-
1. Go to **Settings** (the gear icon) > **SaaS integrations**.
91-
2. Go to your integration, and ensure that the integration displays **CASB+EMAIL** under **Type**.
90+
1. In [Zero Trust](https://one.dash.cloudflare.com/), go to **Email Security**.
91+
2. Go to **Settings** (the gear icon) > **SaaS integrations**.
92+
3. Go to your integration, and ensure that the integration displays **CASB+EMAIL** under **Type**.
9293

9394
:::note
94-
If you do not reach the step to complete Email Security set up:
95+
If you do not reach the step to complete the Email Security set up:
9596

9697
1. Go to **Settings** (the gear icon) > **SaaS Integrations**.
9798
2. Delete the integration, if present. Locate your integration, select **Configure**, then select **Delete**.
98-
3. Follow the steps from the beginning to enable Gmail BCC integration.
99+
3. Follow the steps from the beginning to [enable Gmail BCC integration](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/#enable-gmail-bcc-integration).
99100
:::
100101

101102
## Next steps

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/m365-journaling.mdx

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,10 @@ When you receive an email, the email lands on your Microsoft 365 inbox, and then
1313

1414
To enable Microsoft 365 journaling deployment:
1515

16-
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/).
17-
2. Select **Zero Trust**.
18-
3. Select **Email Security**.
19-
4. Select **Overview**: If you have not purchased Email Security, select **Contact Sales**. Otherwise, select **Set up**.
20-
5. Select **BCC/Journaling**.
21-
6. Select **Integrate with MS** > **Authorize**.
16+
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/) > **Email Security**.
17+
2. Select **Overview**. If you have not purchased Email Security, select **Contact Sales**. Otherwise, select **Set up** > **BCC/Journaling**.
18+
3. Select **Integrate with MS** > **Authorize**.
19+
4. Continue with [Integrate with Microsoft 365](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/m365-journaling/#integrate-with-microsoft-365) to connect your Microsoft integration.
2220

2321
## Integrate with Microsoft 365
2422

src/content/docs/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/manage-domains.mdx

Lines changed: 17 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -8,28 +8,30 @@ sidebar:
88

99
To filter your domains:
1010

11-
1. Select **Settings**.
12-
2. Select **Configured method** and/or **Status**:
13-
* If you select **Configured method**, choose among the following:
14-
* **All**: To view all the domains.
15-
* **MS Graph API**: To view domains connected via MS Graph API.
16-
* **BCC/Journaling**: To view domains connected via BCC/Journaling.
17-
* If you select **Status**, choose among the following:
18-
* **All**: To view Active and No mail flow domains.
19-
* **Active**: To view active domains. A domain is active when the connection is running, and Email Security is able to scan email messages.
20-
* **No mail flow**: To view no mail flow domains. A domain has a "No mail flow" status when no mail flow is detected. You may not have any email traffic or your BCC/Journaling configuration is incomplete.
11+
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/) > **Email Security**.
12+
2. Go to **Settings** > **Domain management** > **Domains**, then select **View**.
13+
3. Select **Configured method** and/or **Status**:
14+
- If you select **Configured method**, choose among the following:
15+
- **All**: To view all the domains.
16+
- **MS Graph API**: To view domains connected via MS Graph API.
17+
- **BCC/Journaling**: To view domains connected via BCC/Journaling.
18+
- **Retro Scan**: To view domains scanned by Retro Scan.
2119

2220
## Edit domains
2321

2422
To edit your domains:
2523

26-
1. On the **Domains** page, locate your domain, select the three dots > **Edit**.
27-
2. If you did not manually add your domain, you will only be able to edit **Hops**. If you manually added your domain, you will be able to edit **Domain name** and **Hops**.
28-
3. Select **Save**.
24+
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/) > **Email Security**.
25+
2. Go to **Settings** > **Domain management** > **Domains**, then select **View**.
26+
3. On the **Domains** page, locate your domain, select the three dots > **Edit**.
27+
4. If you did not manually add your domain, you will only be able to edit **Hops**. If you manually added your domain, you will be able to edit **Domain name** and **Hops**.
28+
5. Select **Save**.
2929

3030
## Prevent Cloudflare from scanning a domain
3131

3232
To unscan domains:
3333

34-
1. On the **Domains** page, locate your domain, select the three dots > **Unscan**.
35-
2. Select **Unscan** again to stop Cloudflare from scanning your domain.
34+
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/) > **Email Security**.
35+
2. Go to **Settings** > **Domain management** > **Domains**, then select **View**.
36+
3. On the **Domains** page, locate your domain, select the three dots > **Unscan**.
37+
4. Select **Unscan** again to stop Cloudflare from scanning your domain.

0 commit comments

Comments
 (0)