

{"id":8472,"date":"2018-03-16T13:49:12","date_gmt":"2018-03-16T13:49:12","guid":{"rendered":"https:\/\/projects.helpline.w3.uvm.edu\/?post_type=ht_kb&#038;p=8472"},"modified":"2024-09-18T15:15:54","modified_gmt":"2024-09-18T19:15:54","slug":"proofpoint","status":"publish","type":"ht_kb","link":"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/proofpoint\/","title":{"rendered":"Proofpoint"},"content":{"rendered":"<p>All incoming uvm.edu mail is filtered through Proofpoint, an anti-spam, anti-malware, anti-phishing service. UVM adopted Proofpoint to replace Sophos PureMessage in June 2019. Messages tagged as spam are automatically filtered into the &#8220;Junk Email&#8221; folder.<\/p>\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>Proofpoint Message Tagging<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>There are a number of factors that Proofpoint uses to determine the legitimacy of a message. If Proofpoint determines that a message may be spam, it adds <strong>SPAM<\/strong> to the subject header, with additional text based on its confidence level.<\/p>\n<ul>\n<li>Over 50% spam confidence\n<ul>\n<li>Subject header added: <strong>[SPAM?:*****] <\/strong><\/li>\n<li>Additional asterisks for every additional 10% spam confidence (ie. [SPAM?:*******] for 70% confidence)<\/li>\n<\/ul>\n<\/li>\n<li>100% spam confidence\n<ul>\n<li>Subject header added: [SPAM &#8211; DEFINITE]<\/li>\n<\/ul>\n<\/li>\n<li>Messages identified as &#8220;low priority&#8221; (e.g. bulk mail, marketing lists) but not spam will have a new header added:\n<ul>\n<li><em>X-Proofpoint-Tag: lowpriority<\/em><\/li>\n<\/ul>\n<\/li>\n<li>All messages will have an <em>X-Proofpoint-Spam-Details<\/em> header which will provide the details of the message&#8217;s scoring and the most relevant rule that has matched.<\/li>\n<\/ul>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>Messages with attachments seem to be delayed<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>There may be some short mail delays (3-4 minutes) for incoming messages with attachments.<\/p>\n<p>These potential delay are caused by a security feature called\u00a0<strong>Attachment Defense<\/strong>. Attachments are run in a\u00a0sandbox virtual machine to check for behaviors identified with malware (unidentified worms, crypto-lockers, etc.).\u00a0The timeout for Attachment Defense is set to 15 minutes.<\/p>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>What's the difference between Spam and Phishing?<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p><strong>Spam<\/strong> is unsolicited email that often attempts to sell a product or service. Typically, spam is addressed to a vast number of people in hopes that casting a wide enough net will increase the likelihood of getting a response.<\/p>\n<p><strong>Phishing<\/strong> is a specific type of spam that attempts to trick you into giving away your personal information, whether it&#8217;s your UVM credentials, your credit card information, or even your Social Security Number.<\/p>\n<p>Phishing attempts are often threatening and time sensitive &#8212; &#8220;Respond by tomorrow or we will delete your account!&#8221; Phishing attempts may appear to come from UVM or some well known company and often include a mix of real and fake email addresses and web links (URLs).<\/p>\n<p>The University of Vermont is invested in maintaining the security of your account and protecting your private information while also ensuring these services don&#8217;t dissuade collaboration and aren&#8217;t overly restrictive. As such, we rely on our users to practice safe computing and be cautious and critical.<\/p>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>How do I know if a message is legitimate or not?<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>It&#8217;s important to always be wary of any emails you receive. Even if you receive an email from a friend, colleague, or family member, it&#8217;s possible this person&#8217;s email credentials have been compromised.<\/p>\n<p>There are several cues that help in determining the legitimacy of an email.<\/p>\n<ol>\n<li>The email is not personalized\n<ul>\n<li>The email isn&#8217;t sent directly to you, and your name is not used in the body of the message<\/li>\n<li>The message was sent to a list of individuals with whom you are unfamiliar<\/li>\n<li>The recipients of this message are hidden<\/li>\n<\/ul>\n<\/li>\n<li>The subject line is intended to shock, but doesn&#8217;t describe the content of the message<\/li>\n<li>The content of the email is awkwardly written and\/or contains spelling and grammatical errors<\/li>\n<li>The email is urgently requesting personal financial information<\/li>\n<li>When you hover over any links in the message for a few seconds, the link doesn&#8217;t match where the sender said the link would go, or the link doesn&#8217;t go to a UVM site<\/li>\n<\/ol>\n<p>When any of these cues appear in an email concerning your UVM account, you shouldn&#8217;t respond or click any links in the email, and you should delete the email.<\/p>\n<p>For more detailed information, see <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/managing-online-safety\/\" target=\"_blank\" rel=\"noopener\">Managing Online Safety: Phishing and Spam<\/a>. If after checking for these cues you are still unsure if the email is legitimate, you can <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/contact\">contact the UVM Tech Team<\/a> for assistance.<\/p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>What should I do if I responded to a phishing attempt, or clicked a link in a phishing email?<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<ol>\n<li>Change your NetID Password at <a href=\"https:\/\/account.uvm.edu\">https:\/\/account.uvm.edu<\/a> as soon as possible.<\/li>\n<li>It&#8217;s possible UVM&#8217;s Identity and Account Management department will catch that your account has been compromised. If so, your account will be locked to protect your information and privacy, and the University&#8217;s privacy as a whole. <strong>To remove this lock, you will need to <a href=\"https:\/\/www.uvm.edu\/it\/identity-and-account-management\">contact Identity and Account Management<\/a><\/strong>.<\/li>\n<li>Though not always necessary, you may also want to change your password for various non-UVM services (personal bank, other email accounts).<\/li>\n<li>If you replied to a phishing email, you may also want to remove the email address from your outlook cache. To do this in Outlook or <a href=\"http:\/\/outlook.cloud.microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Outlook Online<\/a>:\n<ul>\n<li>Start by composing a new email message.<\/li>\n<li>Begin typing the name of the address\/individual you&#8217;d like to remove from the cache. The desired name\/address will display in the auto-complete window.<br \/>\n<a href=\"https:\/\/projects.helpline.w3.uvm.edu\/wp-content\/uploads\/2018\/10\/delete-cached-address.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11541 size-full\" src=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address.png\" alt=\"Outlook Auto-complete list with X button highlighted to the right of a UVM Exchange account\" width=\"386\" height=\"217\" srcset=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address.png 386w, https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address-300x169.png 300w, https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address-50x28.png 50w, https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address-60x34.png 60w, https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-content\/uploads\/2018\/10\/delete-cached-address-100x56.png 100w\" sizes=\"auto, (max-width: 386px) 100vw, 386px\" \/><\/a><\/li>\n<li>When you&#8217;ve found the contact you&#8217;d like to remove, hover your mouse pointer over the contact and then click on the <strong>X\u00a0<\/strong>to remove it.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n<h3>Reporting Proofpoint Tagging Errors<\/h3>\n<p>False positives and false negatives are possible with all email filtering services. Reporting these tagging errors can help improve the algorithm.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--danger  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Please Forward Full Mail Headers<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tEmail headers include information crucial to understanding why a tagging error occurred. <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/forwarding-full-mail-headers\">See our guide on forwarding full mail headers<\/a>.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>Reporting a False Positive<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>A false positive most broadly refers to mail that was tagged as spam, but should not have been.<\/p>\n<p>To report a false positive, please <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/forwarding-full-mail-headers\">forward the message&#8217;s full mail headers<\/a>\u00a0to <a href=\"mailto:not-spam@uvm.edu\">not-spam@uvm.edu<\/a>.<\/p>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>Reporting a False Negative (Spam)<\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>A false negative refers to mail that was\u00a0not tagged by Proofpoint, but should have been. This typically includes spam, unsolicited email, generic scams, or other annoyances.<\/p>\n<p>To report a false negative, please <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/forwarding-full-mail-headers\">forward the message&#8217;s full mail headers<\/a> to <a href=\"mailto:is-spam@uvm.edu\">is-spam@uvm.edu<\/a>.<\/p>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n    \t\t<div class=\"hts-toggle  \"  >\r\n    \t\t\t<div class=\"hts-toggle__title\"><h3>Reporting Phishing Attacks, Malware, or Other Malicious Messages <\/h3><\/div>\r\n    \t\t\t<div class=\"hts-toggle__content\">\r\n    \t\t\t\t<div class=\"hts-toggle__contentwrap\">\r\n    \t\t\t\t\t<\/p>\n<p>If you receive mail that appears to be malicious, but was not tagged by Proofpoint, you may <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/article\/forwarding-full-mail-headers\">forward full mail headers<\/a> to <a href=\"mailto:abuse@uvm.edu\">abuse@uvm.edu<\/a>.<\/p>\n<p>This typically includes:<\/p>\n<ol>\n<li>Phishing attacks targeted at UVM users<\/li>\n<li>Signs of a compromised account (e.g. spam coming from a uvm.edu address)<\/li>\n<li>Terms of Service violations<\/li>\n<li>Malware that ends up in your inbox<\/li>\n<\/ol>\n<p>You may also <a href=\"https:\/\/www.uvm.edu\/it\/dev\/kb\/contact\">contact the UVM Tech Team<\/a> who may work with our Systems Administrators to address this issue.<\/p>\n<p>\n    \t\t\t\t<\/div>\r\n    \t\t\t<\/div><!-- \/ht-toggle-content -->\r\n    \t\t<\/div>\r\n    \t\t\n","protected":false},"excerpt":{"rendered":"<p>All incoming uvm.edu mail is filtered through Proofpoint, an anti-spam, anti-malware, anti-phishing service. UVM adopted Proofpoint to replace Sophos PureMessage in June 2019. Messages tagged as spam are automatically filtered into the &#8220;Junk Email&#8221; folder. Reporting Proofpoint Tagging Errors False positives and false negatives are possible with all email filtering&#8230;<\/p>\n","protected":false},"author":119,"comment_status":"open","ping_status":"closed","template":"","format":"standard","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","footnotes":""},"ht-kb-category":[271,270],"ht-kb-tag":[387,458,521,404,457],"class_list":["post-8472","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-email-and-calendar","ht_kb_category-security","ht_kb_tag-email","ht_kb_tag-phish","ht_kb_tag-proofpoint","ht_kb_tag-security","ht_kb_tag-spam"],"_links":{"self":[{"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb\/8472","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/users\/119"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/comments?post=8472"}],"version-history":[{"count":24,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb\/8472\/revisions"}],"predecessor-version":[{"id":29952,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb\/8472\/revisions\/29952"}],"wp:attachment":[{"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/media?parent=8472"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb-category?post=8472"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/dev\/kb\/wp-json\/wp\/v2\/ht-kb-tag?post=8472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}