Views:
  1. Log in to the TMEMS console.
  2. Go to Logs > Mail Tracking.

    Mail Tracking

    Click the image to enlarge.

The Mail Tracking screen provides the following search criteria:

  • Period - the time range for your query
  • Direction - the direction of messages
  • Recipient - the recipient email address
  • Sender - the sender email address
  • Email Header (To) - the recipient address in the message header
  • Email Header (From) - the sender address in the message header
  • Type - the type of email traffic that you want to query:
    • Accepted traffic - messages that were allowed in by TMEMS for further processing
    • Blocked traffic - attempts to send messages in that were stopped by connection-based filtering at the MTA connection level or by TMEMS incoming security filtering
  • Action - the last action taken on the message:
    • All - all actions will be matched for your search
    • Bounced - TMEMS bounced the message attempted back to the sender because the message was rejected by the downstream MTA
    • Temporary delivery error - TMEMS attempted to deliver the message to the downstream MTA but failed due to unexpected errors. This is a transient state of the message, and a message should not remain in this state for an extended period of time
    • Deleted - TMEMS deleted the entire email message according to the matched policy
    • Delivered - TMEMS delivered the message to the downstream MTA
    • Expired - TMEMS bounced the message back to the sender because the message had not been delivered successfully for a long time
    • Quarantined - TMEMS held the message in quarantine awaiting actions because the message triggered a certain policy rule
    • Redirected - TMEMS redirected the message to a different recipient according to the matched policy
    • Submitted to sandbox - TMEMS submitted the message to Virtual Analyzer for further analysis
       
      This is a transient state of the message, and the state will change once the Virtual Analyzer analysis result is returned or Virtual Analyzer scan exception is triggered.
       
  • Subject - the message subject
  • Message ID - the unique ID of an email message
  • Sender IP - the IP address of the host where the message was sent from
  • Delivered To - the IP address of the host where the message was delivered to
  • Upstream TLS - the version of the TLS protocol used by the upstream server to connect to TMEMS
  • Downstream TLS - the version of the TLS protocol used by TMEMS to connect to the downstream server
  • Downstream DANE - whether DANE authentication is applied to TLS connections between TMEMS and the downstream server
  • Attachment SHA256 Hash - the SHA256 hash value of a message attachment. Specify a SHA256 hash value consisting of 64 hexadecimal characters or leave it blank

    When a valid SHA256 hash value is specified, the Attachment Status field displays with the following options:

    • All: Query all messages containing the specified attachment. This is the default option.
    • Deleted: Query the messages with the specified attachment deleted.
    • Cleaned: Query the messages with the specified attachment cleaned for malware.
    • Bypassed: Query the messages with the specified attachment bypassed.
  • Timestamp - the time a message was received

Click the result timestamp to check the mail tracking details of an inbound/outbound email. The mail tracking summary, Action and Event details are displayed.

Mail Tracking Details 1

Click the image to enlarge.

Mail Tracking Details 2

Click the image to enlarge.

This shows all of the policies on where the email went through. This also indicates if the email has violated any policy and what action has been done.

Actions

Click the image to enlarge.