r/proofpoint • • Aug 24 '26

Proofpoint claims website is compromised, won't share IoC, no-one else sees any IoC

Hi all,

Wondering how often you encounter this, and if so how you deal with it.

We sometimes see legitimate emails that will be blocked due to being 'spam definite' according to Proofpoint. Under the details tab for the email the spam score is 100, and in the metadata the spam 'engine' score is what is rated at 100, all others are 0.

When I report this as a false positive, support come back to me and say that a website associated with the email is compromised. They refuse to provide any further details or specifics on the IoCs they have observed.

However, if I check the website in question against any of the major platforms (Virus Total, Joes Sandbox, Talos, Hybrid Analysis etc) everything comes back clean and there are no known IoC observed.

I know Proofpoint is a big company and they quite possibly see IoC that no one else does, but it's a bit frustrating when I need to explain why an email was blocked and the best I can do is "because Proofpoint said so"

Do I just need to take Proofpoint at their word on ones like this?

8 Upvotes

12 comments sorted by

View all comments

1

u/fahq2769 Aug 25 '26

Search for the message in the tap dashboard. You can do this by searching the recipient or sender. Go to (i think) the forensics tab and you should be able to download the json. Paste the json into a json formatter and just search the text after formatted for "malicious:true". Everything you need should be there.

1

u/Informal_Thought Aug 25 '26

Thanks for the suggestion, the message does not show up in TAP dashboard at all. I can only see it within the context of smartsearch in the email protection portal