Using comment flags against email spoofing

Plan requirement

Subscription Any plan
Access Admin

A visible marker on messages that failed authentication, so the agent sees it at the moment they are deciding.

Turn it on

  1. Open the email security settings in Admin Center.
  2. Enable comment flagging for messages that fail authentication.
  3. Look at a flagged ticket yourself.
  4. Tell agents what the flag means and what to do.

Why a flag rather than a block

Blocking loses genuine customer email, because legitimate messages fail these checks more often than people expect. Flagging keeps the message and gives the agent the context.

It puts the judgement where the judgement belongs.

It only works if agents know

A marker nobody has explained is a marker nobody reads. This is a training step more than a configuration step, and skipping it means the feature does nothing.

What agents should do with one

Nothing special for an ordinary question. For anything sensitive (account changes, personal data, refunds, credentials), verify identity another way before acting.

That rule is short enough to remember, which is why it works.

Look for patterns

Flags clustering on one domain usually mean that company's mail is misconfigured rather than that somebody is attacking you. Worth telling them; it is a favour and it reduces the noise.

Where it matters most

Teams handling account changes, payments or anything financial. If your agents can change a delivery address or issue a refund on the strength of an email, this is worth switching on today.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.