IP Library Granted Patent US 12,689,603
Granted Patent B2
US 12,689,603 · App. 18/420,494 · Granted Jul 21, 2026

Configuring a monitor mode for suspicious content in emails

Inventors: Narendrakumar Jagadishkumar Shah (Ahmedabad, IN); Vivek Rudraduttbhai Yagnik (British Columbia, CA); Sumit Devshibhai Kakadiya (Ahmedabad, IN); John Mears (Carmarthen, GB); Tom Foucha (Southhaven, MS)
Assignee: Sophos Limited
H04L51/212H04L51/08H04L63/145H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,689,603
App. No.
18/420,494
Filed
Jan 23, 2024
Granted
Jul 21, 2026
Kind
B2
Art Unit
2443
USPC
726/22
Abstract

A computer-implemented method includes implementing, at a first computing system, a configuration of a routing journal rule and a connector to configure the first computing system to automatically send copies of inbound emails received at the first computing system to a second computing system that is distinct from the first computing system, wherein the second computing system includes a set of scanners operable to analyze the copies of the inbound emails to detect suspicious content. The method further includes receiving a notification of the suspicious content in a first email of the copies of inbound emails from the second computing system, wherein the notification is generated responsive to one or more of the set of scanners detecting at least the first email as including suspicious content.

Claims (55)

1 . A computer-implemented method to operate an email processing system, the method comprising:

configuring, at a first computing system comprising an email server, a a routing journal rule and a mail connector that cause the email server to, for each inbound email message received via a Simple Mail Transfer Protocol (SMTP) interface:

(a) generate a copy of the inbound email message and route the copy, using a routing header added by the email server, to a second computing system distinct from the first computing system, and

(b) deliver the inbound email message to at least one recipient inbox without waiting for analysis of the copy of the inbound email message;

receiving, from the second computing system, an analysis result generated by executing one or more content scanners on the copy of the inbound email message, the analysis result indicating whether the inbound email message includes non-permitted suspicious content;

transmitting, based on the analysis result indicating the non-permitted suspicious content, an alert to an administrative interface associated with the first computing system;

in response to an administrative command received via the administrative interface, dynamically reconfiguring the routing journal rule and the mail connector such that subsequent inbound email messages are routed to the second computing system for content analysis prior to delivery to recipient inboxes;

receiving, for a subsequent inbound email message, a second analysis result from the second computing system indicating an absence of non-permitted suspicious content; and

delivering the subsequent inbound email message to at least one recipient inbox responsive to the second analysis result.

2 . The method of claim 1 , wherein:

the second computing system is specific to the first computing system, and

the second computing system includes an address associated with the first computing system in its network name.

3 . The method of claim 1 , wherein the administrative command received via the administrative interface is a request to switch from a monitor mode to an active mode to prevent delivery of subsequent inbound email messages with suspicious content.

4 . The method of claim 1 , wherein the one or more content scanners are associated with a respective type of content and are configured to detect whether the copy of the inbound email message includes the respective type of content.

5 . The method of claim 1 , wherein the second computing system is configured to receive copies of outbound email messages and analyze the copies of the outbound email messages for suspicious content, and the method further includes:

receiving a notification of the suspicious content in one of the outbound email messages from the second computing system, wherein the notification is generated responsive to the one or more content scanners detecting at least an outbound email message of the copies of the outbound email messages as including suspicious content.

6 . The method of claim 5 , wherein configuring the routing journal rule includes one or more options selected from a group of: specifying an email address that receives the copy of the inbound email message, specifying the email address that receives the copies of the outbound email messages, specifying a sender of the inbound email message, specifying a type of message to receive, and combinations thereof.

7 . The method of claim 1 , wherein the second computing system is configured to receive copies of internal email messages generated by a user and analyze the copies of the internal email messages for suspicious content, and the method further includes:

receiving a notification of the suspicious content in one of the internal email messages from the second computing system, wherein the notification is generated responsive to the one or more content scanners detecting at least an internal email message of the copies of the internal email messages as including suspicious content.

8 . The method of claim 1 , wherein delivery of the inbound email message is unaffected by routing the copy of the inbound email message to the second computing system.

9 . The method of claim 1 , further comprising:

removing, based on a subsequent administrative command received responsive to receiving the analysis result indicating the non-permitted suspicious content, the inbound email message from the at least one recipient inbox.

10 . The method of claim 1 , wherein configuring the routing journal rule and the mail connector includes modifying an Elastic Load Balancing (ELB) record or a Domain Name System (DNS) Mail Exchange (MX) record.

11 . The method of claim 1 , further comprising generating a report that summarizes copies of the inbound email messages during a particular time period, wherein the report includes one or more features selected from a group of an inbound email message history, an inbound email message summary, a description of suspicious files included in the copies of the inbound email messages, a risk summary, a data loss prevention summary, a license summary, and combinations thereof.

12 . The method of claim 1 , further comprising:

determining a threat level associated with an instance of suspicious content in a copy of a second inbound email message; and

responsive to the threat level exceeding a threshold threat level, removing the second inbound email message from at least one second recipient inbox.

13 . A first computing system that implements an email server, the first computing system comprising:

one or more processors; and

one or more computer-readable media, coupled to the one or more processors and having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

configuring, at the first computing system, a routing journal rule and a mail connector that cause the email server to, for each inbound email message received via a Simple Mail Transfer Protocol (SMTP) interface:

(a) generate a copy of the inbound email message and route the copy, using a routing header added by the email server, to a second computing system distinct from the first computing system, and

(b) deliver the inbound email message to at least one recipient inbox without waiting for analysis of the copy of the inbound email message;

receiving, from the second computing system, an analysis result generated by executing one or more content scanners on the copy of the inbound email message, the analysis result indicating whether the inbound email message includes non-permitted suspicious content;

transmitting, based on the analysis result indicating the non-permitted suspicious content, an alert to an administrative interface associated with the first computing system;

in response to an administrative command received via the administrative interface, dynamically reconfiguring the routing journal rule and the mail connector such that subsequent inbound email messages are routed to the second computing system for content analysis prior to delivery to recipient inboxes;

receiving, for a subsequent inbound email message, a second analysis result from the second computing system indicating an absence of non-permitted suspicious content; and

delivering the subsequent inbound email message to at least one recipient inbox responsive to the second analysis result.

14 . The first computing system of claim 13 , wherein the second computing system is specific to the first computing system and includes an address associated with the first computing system in its network name.

15 . The first computing system of claim 13 , wherein the second computing system is configured to receive copies of outbound email messages and analyze the copies of the outbound email messages for suspicious content, and the operations further include:

receiving a notification of the suspicious content in one of the outbound email messages from the second computing system, wherein the notification is generated responsive to the one or more content scanners detecting at least an outbound email message of the copies of the outbound email messages as including suspicious content.

16 . A non-transitory computer-readable medium with instructions stored thereon that, responsive to execution by one or more processing devices, cause the one or more processing devices to perform operations comprising:

configuring, at a first computing system comprising an email server, a a routing journal rule and a mail connector that cause the email server to, for each inbound email message received via a Simple Mail Transfer Protocol (SMTP) interface:

(a) generate a copy of the inbound email message and route the copy, using a routing header added by the email server, to a second computing system distinct from the first computing system, and

(b) deliver the inbound email message to at least one recipient inbox without waiting for analysis of the copy of the inbound email message;

receiving, from the second computing system, an analysis result generated by executing one or more content scanners on the copy of the inbound email message, the analysis result indicating whether the inbound email message includes non-permitted suspicious content;

transmitting, based on the analysis result indicating the non-permitted suspicious content, an alert to an administrative interface associated with the first computing system;

in response to an administrative command received via the administrative interface, dynamically reconfiguring the routing journal rule and the mail connector such that subsequent inbound email messages are routed to the second computing system for content analysis prior to delivery to recipient inboxes;

receiving, for a subsequent inbound email message, a second analysis result from the second computing system indicating an absence of non-permitted suspicious content; and

delivering the subsequent inbound email message to at least one recipient inbox responsive to the second analysis result.

17 . The non-transitory computer-readable medium of claim 16 , wherein the second computing system is specific to the first computing system and includes an address associated with the first computing system in its network name.

18 . The non-transitory computer-readable medium of claim 16 , wherein the second computing system is configured to receive copies of outbound email messages and analyze the copies of the outbound email messages for suspicious content, and the operations further include:

receiving a notification of the suspicious content in one of the outbound email messages from the second computing system, wherein the notification is generated responsive to the one or more content scanners detecting at least an outbound email message of the copies of the outbound email messages as including suspicious content.

19 . The non-transitory computer-readable medium of claim 16 , wherein the administrative command received via the administrative interface is a request to switch from a monitor mode to an active mode to prevent delivery of subsequent inbound email messages with suspicious content.

20 . The non-transitory computer-readable medium of claim 16 , wherein the operations further include generating a report that summarizes copies of the inbound email messages during a particular time period, wherein the report includes one or more features selected from a group of an inbound email message history, an inbound email message summary, a description of suspicious files included in the copies of the inbound email messages, a risk summary, a data loss prevention summary, a license summary, and combinations thereof.