Defend is an email security tool that evaluates the context, relationships, and message content of your inbound emails. This analysis occurs when emails reach your inbox, helping prevent inbound cyber threats and allowing your admins to identify and act on any future breaches.
Tags
Based on Defend's analysis, incoming emails from outside of your organization will have a colored tag applied. These colorful tags indicate how the email has been classified. The banner's color corresponds to its associated threat level.
These tags let you quickly identify an email's Defend classification before you even open it. Tags can also be selected to view all emails categorized under that tag.
The following color and category tags may be added to your emails, along with an example of each:
| Tag | Color | Description | Example |
|---|---|---|---|
| Graymail | Gray | Non-malicious bulk email, such as a promotional or rewards newsletter, that you may have opted into in the past. | |
| Spam | Gray | Unsolicited bulk email. | |
| First-time sender | Blue | Flags a message from a sender you have not previously received email from. | ![]() |
| Financial | Blue | Flags a message that references billing, payments, or financial account details. | |
| Sensitive | Blue | Flags a message that references account security or other sensitive account activity. | |
| Threat Notification | Blue | Indicates the email is a threat notification containing teachable moments on a Suspicious or Dangerous email. See the Threat Notification section below. | |
| Suspicious | Amber | Flags a message with characteristics commonly associated with phishing, such as urgency or a mismatched sender domain. Suspicious doesn't mean dangerous. It is used to indicate that the user should ensure the email is intended for them. If they're unsure, they should report it using the Phish Alert Button (PAB). | |
| Impersonation | Amber | Flags a message where the sender appears to be posing as a known contact or organization. | |
| Dangerous | Red | Flags a message Defend has identified as a threat.* |
*You may never see a dangerous tag if your admin configured the settings to send dangerous emails to quarantine or be replaced with a threat notification.
Threat Notification
If configured by your admin, Defend may send you threat notification emails to help you recognize phishing attempts. These emails arrive after Defend identifies them as suspicious or dangerous and will be marked with a blue tag in your inbox. Threat notifications replace the original suspicious or dangerous email with information about what Defend detected.
Threat notification emails contain the following information and options:
- Original email details
- Subject
- From address
- Sent time
- Sender location
- Sender relationship history
- Email Analysis Summary
- Provides details for up to five reasons why Defend thought the email could be a phishing attack.
- Report buttons
- Report the original email as "Phish". This option is only available for emails identified as suspicious.
- Report the original email as "Not Phish".
An example threat notification email is shown in the screenshot below.
Productivity Management
Managing your inbox effectively requires distinguishing between different types of bulk communication. Defend categorizes unsolicited or non-essential emails into two main groups:
- Graymail
- Non-malicious bulk email, such as newsletters or marketing updates, that you may have opted into in the past. It is technically wanted at some point, but it can become distracting.
- Spam
- Unsolicited, bulk email that is sent to a large number of recipients, typically for commercial advertising, promotional, or mass marketing purposes, sometimes containing malicious links or attachments.
Depending on your organization's configuration, emails flagged as graymail or spam will either:
- Appear in your inbox with a Graymail or Spam tag.
- Be sent to your Graymail or Junk folder with a Graymail or Spam tag.

