Email Track and Trace with Enhanced View
search cancel

Email Track and Trace with Enhanced View

book

Article ID: 454431

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

This article describes the new functionality of Email Track and Trace Enhanced View, an alternate search experience that returns results faster and removes the limit on the number of matching emails that can be retrieved. Enhanced View is optional: you can switch between it and the classic view at any time, and your choice does not affect your search permissions or the emails you are able to see.

Environment

Email Security.cloud

Resolution

To search for an email in Enhanced View, you choose a time range, then define your search using either Quick Filters or Custom Filters

1 - Select
 Tools
>
Email Track and Trace
.

2 - Turn on the
 Enhanced View 
toggle in the upper-right corner of the page.

 

Note: You can turn the toggle off at any time to return to the classic Email Track and Trace view.

 

3 - Select a Time Range and Choose one of the preset ranges (15m, 30m, 1h, 4h, 12h, 24h, 30d), or click Custom to search a specific number of days (up to 30) or a specific date and time range. 

Note: An email can take up to five minutes to be indexed after it is processed. A search for a very recent time range, such as the last five minutes, might not yet include the most recent emails, and the results for that range may be incomplete.

 

4 - Choose the Quick Filters tab or the Custom Filters tab to define your search. Quick Filters is selected by default and provides the following search fields:

  • Envelope Sender
    and
     To
    : Email address fields. An asterisk (*) can be used as a wildcard, for example
    *@domain.*
    .
  • Subject
    and
     Message ID
    : Text fields. An asterisk (*) can be used as a wildcard
  • Scan Service
    and
    Scan Action
    : Multi-select tiles. You can select more than one tile, for example
     Anti-Malware 
    and
     Anti-Spam
    , to search for emails that match any of the selected values. See 'Reference: Quick Filters' for details.
  • Scan Reason
    : Text field. An asterisk (*) can be used as a wildcard. Search by the explanatory text that a Scan Service logs for its action, for example the specific SPF or DMARC failure reason recorded for a blocked or quarantined email. This is the same text shown in the
     Scan Reason 
    column of the results list and the
     Reason 
    field on the
     Service
    tab of the delivery details panel.
  • Attachment
    : Search for emails with or without an attachment, or by attachment name. An asterisk (*) can be used as a wildcard in the attachment name.
  • Sender IP/ Hostname
    : The IP address or hostname of the sending mail server. An asterisk (*) can be used as a wildcard for each octet, for example
    *.*.*.*
    . CIDR notation is not supported.

Custom Filters lets you build more complex queries against a larger set of fields, including Attachment Checksum, Attachment Count, Attachment Filename, Attachment Size, Direction, Email Size (bytes), Envelope Sender, HELO String, Message ID, Message Reference, Scan Action, Scan Reason, Scan Service, Sending Server Hostname, Sending Server IP, Subject, To, URL, and URL Count.

To add a filter, select a field, select an operator, and enter a value, and then click Add. The available operators depend on the field you select; for example, Attachment Count offers Does not equal, Equals, Is greater than, and Is in between. Each filter you add appears as a chip above the results list. You can combine multiple filters using the AND and OR operators, and use parentheses to group conditions.

5 - Click Run Query