The Mail Tracking screen provides the following search criteria:
- Period - the time range for your query
- Direction - the direction of messages
- Recipient - the recipient email address
- Sender - the sender email address
- Email Header (To) - the recipient address in the message header
- Email Header (From) - the sender address in the message header
- Type - the type of email traffic that you want to query:
- Accepted traffic - messages that were allowed in by TMEMS for further processing
- Blocked traffic - attempts to send messages in that were stopped by connection-based filtering at the MTA connection level or by TMEMS incoming security filtering
- Action - the last action taken on the message:
- All - all actions will be matched for your search
- Bounced - TMEMS bounced the message attempted back to the sender because the message was rejected by the downstream MTA
- Temporary delivery error - TMEMS attempted to deliver the message to the downstream MTA but failed due to unexpected errors. This is a transient state of the message, and a message should not remain in this state for an extended period of time
- Deleted - TMEMS deleted the entire email message according to the matched policy
- Delivered - TMEMS delivered the message to the downstream MTA
- Expired - TMEMS bounced the message back to the sender because the message had not been delivered successfully for a long time
- Quarantined - TMEMS held the message in quarantine awaiting actions because the message triggered a certain policy rule
- Redirected - TMEMS redirected the message to a different recipient according to the matched policy
- Submitted to sandbox - TMEMS submitted the message to Virtual Analyzer for further analysis
This is a transient state of the message, and the state will change once the Virtual Analyzer analysis result is returned or Virtual Analyzer scan exception is triggered.
- Subject - the message subject
- Message ID - the unique ID of an email message
- Sender IP - the IP address of the host where the message was sent from
- Delivered To - the IP address of the host where the message was delivered to
- Upstream TLS - the version of the TLS protocol used by the upstream server to connect to TMEMS
- Downstream TLS - the version of the TLS protocol used by TMEMS to connect to the downstream server
- Downstream DANE - whether DANE authentication is applied to TLS connections between TMEMS and the downstream server
- Attachment SHA256 Hash - the SHA256 hash value of a message attachment. Specify a SHA256 hash value consisting of 64 hexadecimal characters or leave it blank
When a valid SHA256 hash value is specified, the Attachment Status field displays with the following options:
- All: Query all messages containing the specified attachment. This is the default option.
- Deleted: Query the messages with the specified attachment deleted.
- Cleaned: Query the messages with the specified attachment cleaned for malware.
- Bypassed: Query the messages with the specified attachment bypassed.
- Timestamp - the time a message was received