Message tracing: following an email from arrival to delivery

Message tracing in the Conbool portal: how the list is built, filters, status values, the detail view with threat score, transport security and process log, actions from quarantine and how long entries are kept.

Message tracing shows what happened to a single email: who delivered it, how it was scored, which processing steps applied and where it was delivered. It sits inside the tenant under Message tracing and is the starting point for any troubleshooting.

One entry per message and recipient

An entry describes the processing for exactly one recipient. A message to four recipients creates four entries carrying the same message ID. This is intentional, because scoring, delivery path and result can differ per recipient: the same attachment may be delivered to one mailbox and held back for another.

List and filters

The list shows date, sender, recipient, status, type and threat score. Filtering works by domain, sender, recipient, message ID and a period from and to. The visibility switch additionally narrows to inbound, outbound and internal, and the selection can be combined. Further rows are loaded with Load more.

When looking for a specific message, the message ID is the most precise means. It appears in the mailbox in the message headers and in every non-delivery report.

Status values and what they mean

  • Successful: handed to the next server, which confirmed acceptance.
  • Partially failed: with several targets, not every one accepted.
  • Failed: delivery failed permanently, the error status names the reason.
  • Processing and Queued: processing is still running.
  • Marked as spam: delivered, but flagged.
  • Quarantine, DLP quarantine: held back, see quarantine.
  • Blocked, DLP blocked, Rejected: not delivered.
  • Discarded: accepted, but deliberately not passed on for this recipient, for instance on a detected mail loop or when the recipient was filtered out along the delivery path.
  • Released and Being released: delivered from quarantine or currently being delivered.
  • Deleted: the entry was removed.

Detail view

A click on a row opens the single view with several blocks.

General information and message data contain the source IP, size, message ID, SMTP status, envelope status, attachments and the error status. The SMTP status is the state of processing, that is the same value as in the status column. The verbatim answer of the remote server appears in the error status field and in the process log. This answers the most common question in troubleshooting: did the recipient server accept or reject, and with what reason.

MailGuard shows the threat score, the individual scoring steps and the detected threats with their category, for instance phishing, malware, suspected fraud or bulk mail. If the policy ran in audit mode, this block also states which action would have applied in enforce mode. The background is described under audit and enforce.

Transport security states separately for inbound and outbound how encryption took place.

  • DANE means the fingerprint from the recipient's DNS was verified.
  • MTA-STS means a valid certificate of the recipient was required.
  • TLS stands for opportunistic encryption, the recipient domain publishes neither DANE nor MTA-STS.
  • unencrypted appears when the remote server offers no STARTTLS.
  • not recorded means the transaction took place but the method was not captured.

For the outbound path the label appears only where delivery actually happened. A blocked or held message has no transport leg and therefore no label.

SecureMail shows signature and encryption per direction, plus algorithm, mode, the rule that applied and the result of the key lookup including the reason if no key was found. A not found is not a failure but the statement that no key was available for that address.

Further blocks appear depending on the processing: applied disclaimers, link clicks with allowed or blocked, the sandbox result, the marking as a calendar item or read receipt, and the process log with the messages of the processing in chronological order.

Actions from the view

For a held message, release, reject and delete are available. If an attachment was sanitised, the stored original can be delivered or requested as soon as the threat score is above the threshold for self-release.

The safe mail preview shows the content rendered, without active parts. It is bound to the Content inspection by administrators setting in the MailGuard settings and is not available without that permission. Looking into somebody else's message is recorded in the audit log and shown to the accessing person beforehand.

Who sees which entries

The view requires the message tracing permission. Without it, the menu entry does not appear. Recipients without an administrative role see the held messages of their own mailbox and can trigger the release from there. Which role carries which rights is described under users and roles.

How long entries are kept

The retention period is set in the MailGuard settings under Retention period. The default is 90 days, adjustable between 7 and 365 days. An empty field means unlimited.

After expiry a daily run removes the stored message including its attachments. The entry itself remains for evidence and analysis and then carries the label retention period expired. Preview and release are no longer possible from that point, while the scoring and the history stay readable.

Limits

Message tracing shows what the gateway saw. Mail between two mailboxes of the same organisation is usually delivered locally by the mail server and never reaches the gateway, so it does not appear here. Complete capture of those messages comes from connecting the archive through journaling or a copy by BCC.

If the same message reappears every minute, that is not a display question but a mail loop. The causes and the figures of the loop protection are described under limits and headers and Exchange connectors.