Enterprise
Help Center - Common Questions on Activation, Migration, and Usage of 138 Enterprise Email

Summarizes common questions about 138 Enterprise Email regarding custom domain binding, email migration, multi-device login, anti-spam settings, and global email delivery, providing enterprise users with clear usage guidelines and service boundary descriptions.

How to preserve evidence for email security breaches in enterprise environments?

To preserve evidence for email security breaches, immediately isolate the affected account, capture logs of unauthorized access or sent emails, and retain original message headers with full routing and authentication data. Use your email administrator panel to export login records, IP addresses, and timestamps—138 Enterprise Email provides attack logs and sender authentication mechanisms (SPF, DKIM, DMARC) to trace spoofing or unauthorized activities. Ensure you document: 1) Time and source of breach, 2) Affected accounts/domains, 3) Actions taken (e.g., password reset, forwarding rules disabled). Note that forensic accuracy depends on timely action; logs may rotate periodically. For legal or compliance reporting, consult your IT team or legal advisor to validate evidence integrity. If using 138 Enterprise Email, access admin logs via the official service portal or contact support for assisted retrieval within contractual boundaries.
Additionally, immediately change the password and revoke suspicious client or dedicated passwords, check automatic forwarding, filtering rules, aliases, and security verification information, and review login, attack, and sending logs to record time, IP, and behavior.