Enterprise

Help Center

Answers common questions about 138 Enterprise Email regarding activation, migration, multi-device configuration, account management, and global email sending and receiving, helping enterprise users quickly identify usage conditions and service processes.

Help Center
  • Can Multi-Factor Authentication (MFA) Prevent Email Account Takeover?

    Yes, multi-factor authentication (MFA) significantly reduces the risk of email account takeover by requiring additional verification beyond passwords, such as codes from authenticator apps or SMS. For enterprises using services like 138 Enterprise Email, MFA adds a critical layer of security against unauthorized access, especially for accounts handling sensitive data or global communications. However, its effectiveness depends on proper implementation—ensure SPF, DKIM, and DMARC are configured to complement MFA, as these sender authentication mechanisms help prevent spoofing and phishing attempts that could bypass single factors. Note that no security measure guarantees 100% protection; MFA mitigates risks but should be part of a broader strategy including regular monitoring and employee training. To set up MFA for your enterprise email, access your account management portal, enable the feature in security settings, and follow prompts for device linking. For tailored configuration support or migration assistance, contact 138 Enterprise Email's official service team to ensure compliance with your organization's needs.

    View details

  • What should be included in enterprise email security training for corporate teams?

    Enterprise email security training should cover foundational protocols like SPF, DKIM, and DMARC configuration to authenticate senders and prevent spoofing, password management including strong password policies and two-factor authentication, and phishing recognition with reporting procedures for suspicious emails. Implementation requires domain ownership, administrative access for configuration, and employee readiness for protocol adoption. Note that training effectiveness depends on regular updates and organizational compliance; 138 Enterprise Email provides built-in security features like spoofing alerts and attack logs, but human vigilance remains critical. For tailored deployment guidance, consult 138's official support to align training with your specific domain and security setup.
    Additionally, training should address account recovery procedures for forgotten passwords, including self-service recovery via bound mobile phones or administrator reset for ordinary users, and emphasize that official customer service typically does not directly set passwords for sub-accounts.

    View details

  • How to Remove Your Business Email from Blacklists: Diagnosis and Recovery

    To remove your business email from blacklists, first identify the listing source using tools like MXToolbox or Spamhaus, then resolve the underlying issue—often caused by misconfigured SPF/DKIM/DMARC records, compromised accounts, or spam-like sending patterns. For 138 Enterprise Email users, ensure SPF, DKIM, and DMARC are properly configured per the platform’s built-in security features (e.g., sender authentication, spoofing alerts) to prevent recurrences. After fixes, request delisting from each blacklist operator via their official process, which may take 24–72 hours. Note: Delisting success depends on the blacklist’s policies; persistent issues may require reviewing sending practices or consulting 138’s official support for domain-specific diagnostics. Next step: Verify your domain’s authentication settings in the 138 admin portal and monitor blacklist status regularly.

    View details

  • How to prevent CEO email impersonation attacks in enterprise email systems?

    To prevent CEO email impersonation attacks, implement sender authentication protocols (SPF, DKIM, DMARC) for your custom domain email system, enable spoofed email identification features, and train staff to verify unexpected requests via secondary channels. 138 Enterprise Email provides built-in security measures including SPF/DKIM/DMARC support, unknown sender alerts, and multi-device access controls. These features help detect and block unauthorized senders mimicking executives. Note that no system guarantees 100% interception, especially if credentials are compromised. For implementation, ensure your domain is properly configured in the admin portal, activate security alerts, and establish internal verification procedures for financial requests. If attacks occur, analyze email headers through the management console and contact support for incident response guidance. Enterprises should combine technical controls with employee training for comprehensive protection.

    View details

  • How does 138 Enterprise Email help prevent and respond to fake payment request emails?

    138 Enterprise Email provides multiple built-in security layers to detect and respond to fraudulent payment requests. First, enable the platform's spoofed email identification and unknown sender alerts in admin settings to flag suspicious emails requesting payments. Second, verify sender authenticity using SPF, DKIM, and DMARC authentication mechanisms that validate whether emails actually originate from claimed domains. Third, implement strong password policies and secondary verification for financial and admin accounts to prevent unauthorized access that could generate fraudulent emails.

    If you receive a suspected fake payment request: 1) Do not click links or attachments 2) Check the sender's authentication status via header details 3) Report to your email administrator immediately 4) Administrators should review login logs and sending history for anomalies 5) Reset passwords and revoke client access if compromise is suspected.

    Boundary note: While 138 Enterprise Email provides detection tools and authentication protocols, ultimate verification of payment requests requires human judgment and external confirmation processes. The system cannot guarantee prevention of all socially engineered attacks.

    Next steps: Ensure your administrator has configured SPF/DKIM records properly and enabled spoofing alerts. Conduct employee training on identifying suspicious payment requests. For suspected account compromises, contact official support at kf@138.gz.cn with relevant logs and headers.

    View details

  • How to handle malware attachments in business email systems?

    Business email systems like 138 Enterprise Email automatically scan and quarantine malware attachments using integrated security protocols. Detection relies on real-time scanning for known threats and behavioral patterns. When identified, attachments are blocked, and users or administrators receive alerts. For handling, access the service portal to review quarantined items, delete malicious files permanently, and notify affected parties if necessary. Ensure SPF, DKIM, and DMARC are configured to reduce spoofing risks, as supported by 138's platform. Effectiveness depends on up-to-date threat databases; novel or encrypted malware may require manual intervention. If infection is suspected, immediately reset passwords, check login logs for anomalous IP addresses, and contact official support for assistance. Always avoid opening attachments from unverified senders and train staff on phishing recognition.

    View details

  • How to protect procurement emails from vendor invoice fraud?

    To protect procurement emails from vendor invoice fraud, implement sender authentication protocols, verify unusual payment requests through secondary channels, and train staff to recognize red flags. 138 Enterprise Email supports SPF, DKIM, and DMARC to authenticate legitimate senders and detect spoofed emails. It also provides alerts for unknown senders and allows centralized management of vendor communication accounts. However, no system guarantees 100% security—always confirm payment changes via phone or in-person verification. For implementation, ensure your domain is properly configured in the admin console and educate your team on checking email headers for discrepancies. If you suspect fraud, immediately contact your IT admin and report to official channels. For specific setup guidance, refer to 138's official support portal or contact their direct service team.

    View details