When a threat is detected by Inbound Shield, admins have an option of automatically sending notifications to the recipient of the email, the reviewer team, or both. This can be selected from the “Secondary actions” menu under any section of the “Threat Prevention Rules” section.
By clicking on the “Notification Options” button, you can configure when recipients and reviewers should receive notifications about detected threats.

Configure Notification Options:
The Configure Notification Options pop-up allows administrators to configure threat notifications for reviewers, recipients, and release requests. The settings are organized into three tabs, each containing options specific to a different notification type.
Reviewer Notification – Configure notifications sent to Inbound Shield reviewers.
Recipient Notification – Configure notifications sent to end users when threats are detected in emails sent to them (this includes Personal Reviewers).
Recipient Release Request Notification – Configure release request notifications sent to reviewers from end users.
.png)
Notification Timing:
Both Reviewer Notifications and Recipient Notifications support the same notification delivery options. Notifications can be sent immediately when a threat is detected or grouped into scheduled notifications delivered at predefined intervals.
When Notify immediately is selected, reviewers or recipients receive a separate notification for every detected threat.
.png)
Scheduled notifications consolidate multiple detected threats into a single report, reducing the number of notification emails sent to reviewers or recipients.
The available notification schedules are:
Notify immediately
Every hour
Every 3 hours
Every 6 hours
Every 8 hours
Custom notification times
Scheduled notifications are delivered as a table that groups detected threats by threat category (such as Malicious or Spam). Each detected threat appears in a separate row, with the available actions displayed on the right side of the notification.
.png)
Reviewer Notification
The Reviewer Notification tab controls the notifications sent to reviewers.
Notification Email Title (Immediate Notification)
Customize the subject line of immediate reviewer notifications.
Supported dynamic fields:
{{RECIPIENT_EMAIL}} – Displays the recipient's email address.
{{EMAIL_SUBJECT}} – Displays the subject of the detected email.
{{COMPANY_NAME}} – Displays your organization name.
If left empty, the default Trustifi notification title is used.
Notification Email Title (Scheduled Notification)
Customize the subject line of scheduled reviewer notification emails.
Supported dynamic fields:
{{COMPANY_NAME}} - Displays your organization name.
{{DETECTED_THREATS}} - Displays the number of threats included in the scheduled notification.
If left empty, the default Trustifi notification title is used.

This notification contains extensive information about the detected threat, as well as a link to review the full email threat analysis and take actions such as releasing the email or blocklisting the sender.
Note: Immediate notifications sent to recipients will appear similar, but by default recipients will not be able to review and take actions on detected emails assigned to them.
You can grant recipients permissions to review and take actions on their own detected emails (with the exception of malicious emails) by selecting “Allow recipient control” in the threat prevention rules. You can find more information on the threat prevention rules in this guide.

Recipient Notification
The Recipient Notification tab controls notifications sent directly to end users when threats are detected in emails sent to them.
Notification Email Title (Immediate Notification)
Customize the subject line of immediate recipient notifications.
Supported dynamic fields:
{{RECIPIENT_EMAIL}} - Displays the recipient's email address.
{{EMAIL_SUBJECT}} - Displays the email subject.
{{COMPANY_NAME}} - Displays your organization name.
Notification Email Title (Scheduled Notification)
Customize the subject line of scheduled recipient notifications.
Supported dynamic fields:
{{RECIPIENT_EMAIL}} - Displays the recipient's email address.
{{COMPANY_NAME}} - Displays your organization name.
{{DETECTED_THREATS}} - Displays the number of threats included in the scheduled notification
Custom Message
Add an optional custom message that will appear in recipient notifications.
The message supports HTML formatting and can include the following dynamic fields:
This can be used to provide release instructions, security guidance, or other organization-specific information.
User Notification Timing Configuration
Enable User Notification Timing Configuration to let recipients manage their own notification schedule from their personal Inbound Email Activity page.

Note: Recipient notifications are similar to reviewer notifications. By default, recipients cannot release quarantined emails themselves. To allow recipients to manage eligible quarantined emails, enable Allow Recipient Control in the applicable Threat Prevention Rule.
By default only admins and reviewers can set custom notification times, however this setting can be enabled for end users by checking the box for “Allow users to set their own custom notification times”.
When this setting is enabled, users can configure their own threat notification settings by going to their personal inbound email activity page in the Trustifi portal and clicking on the “Quarantine Notifications” button.

Customize Reply-To Address
Specify an email address to be used as the Reply-To address for recipient quarantine notifications.
If this field is left empty, replies will be sent to the Primary Reviewer by default.
When enabled, scheduled recipient notifications include a Review all emails button that directs users to their Email Activity page in the Trustifi Portal, where they can review all detected threats included in the notification.
Display Threat Detection Tag Information
When enabled, scheduled recipient notifications display a threat detection tag for each detected threat.
The tag identifies the type of threat detected (for example, Spam, Malicious, or Phishing), providing recipients with additional context about why the email was detected.
Recipient Release Request Notification
When recipients cannot release their own quarantined emails, e.g. when the email was detected as “Malicious”, admins can allow recipients to submit a request for the reviewer team to release this email.
This can be done by selecting the “Allow recipients to request release” check box.

In addition, you can customize some aspects of the release request email:
Release Request Recipients: Specify one or more email addresses that should receive release requests.
Multiple email addresses can be entered, separated by commas.
If this field is left empty, release requests are sent to the Primary Reviewer.
If mailbox-specific reviewers are configured, release requests are automatically routed to the reviewer assigned to that mailbox.
Release Request Email Title: Customize the subject line of release request emails.
The following dynamic fields can be used:
{{RECIPIENT_EMAIL}} – Displays the recipient's email address.
{{EMAIL_SUBJECT}} – Displays the email subject.
{{COMPANY_NAME}} – Displays your organization name.
If this field is left empty, the default Trustifi subject line will be used.
Use "From" Address of the Recipient: When enabled, release request emails are sent using the recipient's email address as the From address instead of the default Trustifi Service mailbox. This allows reviewers to reply directly to the recipient if additional information is required before releasing the email.