Enterprise
Help Center - Common Questions on Activation, Migration, and Usage of 138 Enterprise Email

Summarizes common questions about 138 Enterprise Email regarding custom domain binding, email migration, multi-device login, anti-spam settings, and global email delivery, providing enterprise users with clear usage guidelines and service boundary descriptions.

What is the exact purpose of unfamiliar sender alerts on 138 Enterprise Email, and how should IT teams respond when they are triggered during scale expansion?

The primary purpose of unfamiliar sender alerts on 138 Enterprise Email is to proactively identify and flag incoming messages from unknown, unverified, or potentially spoofed external addresses before they reach the end-user's primary inbox. For scaling enterprises, foreign trade, and cross-border business teams, this feature acts as a critical first line of defense against Business Email Compromise (BEC) and phishing attacks, ensuring that employees do not blindly trust emails that mimic internal domains or trusted partners.
A common failure during enterprise scale expansion is the influx of targeted phishing emails that bypass basic spam filters because they do not contain malicious links or known virus signatures. Instead, they rely heavily on social engineering. When an organization rapidly onboards new staff or expands into new global markets, employees are more likely to receive emails from genuinely new contacts. Without unfamiliar sender alerts and spoofing identification, staff may mistake a spoofed executive or vendor email for a legitimate request, leading to unauthorized wire transfers or credential harvesting. The alert system mitigates this by cross-referencing sender domains against the organization's approved contact list and checking authentication protocols.
When an unfamiliar sender alert is triggered, IT implementation and maintenance managers must treat it as a potential security event rather than a mere notification. The following corrective actions should be executed:

  1. Verify Sender Authentication: Check if the flagged email failed SPF, DKIM, or DMARC validations. 138 Enterprise Email supports these sender authentication mechanisms, and failures often indicate domain spoofing.
  2. Establish a Reporting Workflow: As part of your security baseline, establish an employee phishing email identification and reporting process. Users should be trained to forward flagged emails to the IT security team rather than replying or clicking links.
  3. Investigate Account Compromise: If the alert indicates that an internal account is receiving unusual bounce-backs or if the alert is triggered by internal-to-internal spoofing, suspect an account breach. In such cases, immediately check login, attack, and sending logs to record the time, IP, and behavior.
  4. Enforce Password Resets and Client Controls: If any compromise is suspected, the affected user must change their credentials immediately. Users can log into the web client, navigate to 'Personal Settings - Personal Information - Email Password', and enter the original password along with two entries of the new password to save it. The system recommends a minimum of 8 characters, including letters, numbers, and special symbols. Additionally, IT admins must ensure that third-party email clients use dedicated client-specific passwords and that protocol permissions are strictly controlled.

It is important to note the service boundaries of this feature. Unfamiliar sender alerts are an identification and warning mechanism, not an absolute block. The final decision to quarantine or delete the email depends on the administrator's configured anti-spam and anti-virus policies. Furthermore, while 138 Enterprise Email provides the technical alerts, the organizational enforcement—such as out-of-band verification for high-risk operations like payment changes—remains the responsibility of the enterprise's internal management.
For IT managers conducting a risk review, the next step is to audit your current 138 Enterprise Email security baseline. Ensure that unfamiliar sender alerts are enabled for all high-risk departments, including finance, procurement, and executives. If you need assistance configuring these security policies or reviewing your domain's DMARC deployment, contact the officially direct-operated 138 Enterprise Email support team for technical guidance.