32Guards Recall

32Guards Recall extends NoSpamProxy to include the ability to process or neutralise messages that have already been delivered. This means that security measures can still be implemented even if a threat is only identified after delivery. Data processing is carried out via the Recall Service, which handles communication with Microsoft 365 and the necessary cloud services. See Configuring recall actions.

Requirements

The following requirements must be met in order to use 32Guards Recall:

  • Supported version of NoSpamProxy

  • Valid licence for NoSpamProxy Protection ATP

  • Recall Service Installed

  • Network connection between the intranet role and the Recall Service

  • Availability of the required cloud services

  • Configured 32Guards filter and 32Guards action.

NOTE: If the NoSpamProxy Command Center and the Recall Service are running on different systems, an accessible server address must be configured. It is not possible to use `localhost` in this scenario.

How it works

Emails are processed via the Recall service, which acts as an intermediary between NoSpamProxy, the 32Guards services and Microsoft 365.

Recall service

The Recall service receives alerts about threats identified retrospectively and makes these available to NoSpamProxy. It acts as the link between the 32Guards services and the local NoSpamProxy installation.

Exchange Connector Service

The Exchange Connector Service processes recall alerts and carries out the configured actions in the users’ mailboxes. Depending on the configuration, it can

  • send alerts,

  • replace emails,

  • rchive messages or

  • provide status information for message tracking.

Procedure

  1. An email is initially delivered in the usual way.

  2. At a later stage, the message is classified as security-related.

  3. The Recall service communicates with NoSpamProxy.

  4. NoSpamProxy carries out the configured action for the message in question.

  5. The action is logged in Message Tracking on the 32Guards tab.

Typical use cases

32Guards Recall can, for example, be used when

  • a suspicious email is only recognised after it has been delivered,

  • if new information comes to light regarding a message that has already been delivered,

  • a threat is subsequently classified as critical, or

  • security officers must respond to an incident.