Alert Center for emails -- mark as phishing, delete, or quarantine?

hanker
New Contributor III

I'm a little lost on how to deal with phishing emails when they come across the Alert Center.

Usually what I do is mark as phishing and then delete. Is that necessary? Should I be quarantining them instead? Do I need to delete if I do the mark as phishing?

3 REPLIES 3

ddelboccio
Contributor III

I'm pretty sure emails that you are seeing in the Alert Center marked as phishing are already in user's SPAM folder.  There really should be any further action needed.  

Or are you looking at the Security Center Dashboard?

Or using the investigation tool?

hanker
New Contributor III

 You're right about the alerts in alert center already being in phishing.

I'm using the Investigation tool afterwards and sometimes find additional that aren't yet identified that I'm not quite sure how to address.

ekramer
New Contributor II

I agree with @ddelboccio -- If the alert is for a message marked as phishing, then it has already been marked as phishing for that/those users, but if other users also received the same email, or a similar email and have not already marked it as phishing, then taking this action at an administrative level is a good practice.  Sometimes it takes some further investigation (i.e. messages with similar subjects, DKIM domains, etc.) to find the additional messages.  Spend as much time on it as you feel comfortable!

Here's an article which may help provide some guidance: https://support.google.com/a/answer/11123535