Gather in one place all the emails that collaborators marked as suspicious.
Triage each report: review content, headers, attachments, and links before making a decision.
Classify each incident by category (Threat, Spam, Clean, Unknown) and track its status from start to finish: Received → Under Review → Resolved.
Reply to the collaborator who reported it with a message based on the resolution type chosen.
Leave a complete traceability of each action in the incident's history.
Navigation: Amenazas → Incidentes
Inbox
Go to Amenazas → Incidentes. You will see the Inbox with the list of reported emails.
The list shows the columns: From, Category, Subject, Reported By, and Reported On.
Filter by status using the tabs at the top: All · Received · Under Review · Resolved.
Use the Search bar to find a specific report by sender, subject, or reporter.
When you hover over a row, quick actions appear on the right: delete, change status, classify, download, and reply to the reporter.
Click on any row to open the Incident Detail.
Incident Detail
The header shows: the subject, the status label (Under Review / Resolved), the category label (Threat / Spam / Clean / Unknown), the sender (From), the recipient (To), and a trash icon to delete.
Below appears a strip with the report data: From, Received On, Reported By, Reported On, and IP Address.
Available tabs:
Preview — shows the rendered email as the user received it.
Raw Message — raw content of the email.
Headers — technical headers of the message.
Attachments — list of detected attachments.
Domain & URLs — information about the sender (domain) and all URLs found in the email.
History — records every status change, every category change, and every reply sent, along with the author and date/time.
Reply to the Reporter
From the incident detail (or from the row's quick action), open Reply to User.
Choose a Resolution Type:
Phishing — real threat: warns the user.
False positive — legitimate email: reassures the user.
Under review — still being analyzed.
Spam — unwanted email, no risk.
Custom response — you write a custom text.
The Preview shows the exact message the reporter will receive based on the chosen type.
If you choose Custom response, the free text field is enabled along with the Move to category dropdown (options: Keep current category · Threat · Spam · Clean · Unknown).
Turn on the "Mark as Under Review upon sending" checkbox to automatically update the incident's status when sent.
Click Send Response to confirm (or Cancel to discard). Once sent successfully, a confirmation notice appears and the incident updates its status and category.
Every reply and every status or category change is recorded in the History tab.
What do the categories mean?
Threat = confirmed malicious email. Spam = unwanted email with no risk. Clean = legitimate email. Unknown = not yet classified.
What is the difference between status and category?
The status indicates what stage of the process the report is in (Received, Under Review, Resolved). The category indicates what type of email it is (Threat, Spam, Clean, Unknown).
Can I change the category while responding?
Yes. With the Custom response option, you can use Move to category to reclassify the incident in the same step.
Where can I see the URLs and domain of the reported email?
In the Domain & URLs tab within the incident detail.
How do I know what happened to an incident and who managed it?
In the History tab, which lists every action along with the user who performed it and the exact date/time.
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap