When you go to Analytics > Email Insights and view the Log, Messages or Quarantine messages, you can click at the beginning of a row to view the following additional details about a message.

Details

Following is an alphabetical list of the additional details this tab displays. Some fields apply to logs only or messages only, as noted.

  • Action: Describes the action that the service took on the email. This field appears only when you view a log's details.
  • Attachment Count: The number of attachments, if any.
  • Attachments: List of file names and types of attachments, if any.
  • Client Trans Time: This field appears only when you view a log's details.
  • Destination IP: The IP address of the recipient email server. This field appears only when you view a log's details.
  • Direction: Indicates if the email was inbound to the organization or outbound from the organization.
  • DLP Dictionaries: List of DLP dictionaries that were matched, if applicable.
  • DLP Engine: DLP engines that were matched, if any.
  • Is Retry: Indicates if this transaction was retried. This field appears only when you view a log's details.
  • Log ID: The unique identifier that the service assigned to the email message. All logs associated with a message have the same log ID.
  • Message ID: The unique identifier of the message that the mail server adds to the header when the message is first created. This field appears only when you view message details.
  • Message Size: The email size, in bytes.
  • Policy Action: Displays the action that the service took, based on the applicable email policy. This field appears only when you view a log's details.
  • Sender: The email address of the sender.
  • Server Response Code: This field appears only when you view a log's details.
  • Server Response String: This field appears only when you view a log's details.
  • Server Trans Time: This field appears only when you view a log's details.
  • Source IP: The IP address from which the email was sent.
  • Spam Algorithms: Spam algorithms detected, if any.
  • Spam Score: The spam score (1-100) that the service assigned the email.
  • SSL Deliver: Indicates if the email was sent over SSL. This field appears only when you view a log's details.
  • SSL Receive: Indicates if the email was sent over SSL. This field appears only when you view a log's details.
  • Status: Indicates if the message was delivered, dropped or quarantined. If the message has multiple recipients, it also indicates the number of recipients with the same status. For example, if the status is Delivered (2), then this means that the message was delivered to two recipients. If there were more recipients, then you'll know that the message was not delivered to all recipients, and you can view the email's status for all recipients in the Recipient's tab. This field appears only when you view message details.
  • Subject: The text in the Subject line of the message. This field appears only when you view a log's details.
  • Threat Name: The name of the threat that was detected, if any. This field appears only when you view message details.
  • Time: The date and time of the transaction.
  • Threat Super Category: Indicates if the service detected a virus, spyware, or other malware. This field appears only when you view message details.
  • Threat Category: Specifies the virus, spyware or malware type that was detected, if any. This field appears only when you view message details.

Recipients

This tab lists the email addresses of the users to whom the email was sent and the email status.

Message History

This tab displays a chronological list of the transactions that occurred for the given message. For example, for an inbound message that was quarantined and released, it displays when the message arrived, when it was quarantined, and when it was released. You can filter the list by recipient.