Email Safe Lists, Block Lists & False Positives
Audience: Email Security Administrators.
Purpose: Manage allowlist/blocklist entries and submit misclassified emails to Proofpoint.
Overview
Temporary allowlist/blocklist entries help manage email flow while maintaining security. Always include a date and incident number in comments to enable periodic cleanup.
Submitting False Positives
When legitimate email is incorrectly quarantined, submit it to Proofpoint for scoring adjustment.
Method 1: Report from Quarantine (Recommended)
This is the preferred method as it provides extra diagnostics.
Report Steps
- In Quarantine, check the message to report
- Click Options → Report
- Select FP (Legitimate Mail)
- Click Report Message
- Note the Reference ID displayed in the upper left
Method 2: Open Support Case
Support Case Steps
- Open an Email Classification Errors (FN/FP) case type
- Provide the Reference ID from the quarantine report
- Use "Method A" to supply the reference ID
Open cases as Email Classification Errors (FN/FP) type, not default Support type. This routes directly to Threat Operations and prevents delays.
Submitting False Negatives (Spam)
When spam reaches inboxes, report it to improve Proofpoint's filtering.
Open FN Case
- Open an Email Classification Errors (FN/FP) case type in the PCSC portal
- Threat Operations will review the messages and scoring
- Interact with the team via the case for questions
Report from Spam Reporting Group
If part of a Spam Reporting group:
- PPS administrator opens a Support Call
- Admin reports the FN from your Quarantine's Audit folder
- Reference ID is returned
- Include reference ID in the Support call
Important Notes
Why Not Paste Messages Into Cases?
Proofpoint data analysts use tools requiring specific message formats. Attached messages can be converted, but copied text cannot without manual overhead.
Why Not Forward Emails?
Forwarding alters message headers and content, making forensic analysis unreliable.
What About Filter Logs?
Filter logs show that a message was discarded but not why. The actual message is needed for proper analysis.
Domain/Sender Blocks
If email from certain domains is being blocked:
- Find blocked messages in Quarantine
- Report as False Positive
- Proofpoint will determine the issue and update algorithms
Resources
| Resource | Link |
|---|---|
| Spam Monitoring Guide | Proofpoint Community |
| Spam Reporting Group FAQ | Proofpoint Community |