Overview
This guide walks you through the complete Threat Response process, from selecting mailboxes to viewing scan results.
Step 1: Selecting mailboxes and choosing the “Threat Response” action
Navigate to the Threat Response page (Inbound Management > Threat Response)
Click the "Create New Threat Response" button
The Threat Response wizard window opens
Select which mailboxes to scan and click “Next”
All mailboxes - Scans every protected mailbox
Specific mailboxes - Select individual mailboxes from the list
Step 2: Selecting an action
Choose what you want to search for or scan. Click "Next" after selecting an action.

Rescan
Performs a general scan to find all types of threats and spam
No additional input required
Results are determined by your existing threat prevention rules (found under Threat Prevention tab) and your allow/block lists (found under Allow/Block Lists tab)
Search Links
Searches for specific URL(s) you provide
If found, the selected result action will be applied to the email
Search Files
Searches for specific file(s) you provide
Requires uploading the actual file
If you do not have the file and wish to search by file name only, use "Search Keywords" instead
Search Senders
Searches for emails sent from specific sender addresses
If found, the selected result action will be applied to the email
Search Headers
Searches for emails containing specific headers (key and value pairs)
If found, the selected result action will be applied to the email
Search Keywords
Searches for emails containing specific keywords or phrases
Scans the email body, subject line, and attachment names
If found, the selected result action will be applied to the email
Step 3: Select Conditions
Define the conditions and result action for emails that match your search.
Result Actions:
Review
The email content will be displayed for manual review
No automatic action is taken on the email
Delete Email
The email will be permanently deleted from the mailbox
⚠️ This action cannot be undone
Scan Parameters
Number of last emails to scan for each mailbox:
Select how many emails to scan per mailbox
Emails are scanned chronologically from newest to oldest
Maximum: 1,000 emails per mailbox
Perform Threat Response for this date range
Define the time range for the search (From date - Until date)
Optional Conditions
Notify me: When enabled, a notification email will be sent when the operation is finished.
Scan Sent Items Folder: Will also scan emails in the sent items folder.

Step 4: Summary & Execution
Review the summary of your Threat Response configuration
To modify any settings, click the "Back" button
When ready, click the "Run" button to begin the scan
Note: The scan process duration varies depending on the number of mailboxes and emails being scanned.

Step 5: Viewing results
Once the process is finished, you can view the results in the “Threat Response” tab.
Click on the “Actions” menu next to the “Threat Response” you’ve created.

When you click on the “Show Details” button, a new table will open which will show you a detailed list of:
Which mailboxes the Threat Response process was performed on
The subject of the emails that match the search criteria
The matched item that was found in those emails
The message ID for each matched email
The date that those emails were sent