Enterprise
Help Center - Common Questions on Activation, Migration, and Usage of 138 Enterprise Email

Summarizes common questions about 138 Enterprise Email regarding custom domain binding, email migration, multi-device login, anti-spam settings, and global email delivery, providing enterprise users with clear usage guidelines and service boundary descriptions.

What are the immediate actions an administrator should take if a suspicious login or unauthorized outbound email activity is detected on our 138 Enterprise Email account?

Direct Conclusion: Upon detecting a suspicious login or unauthorized outbound activity, the administrator must immediately terminate active sessions, force a password reset for the affected account, and initiate a log review to identify the scope of exposure. This process leverages 138 Enterprise Email's official direct-operated support model to ensure rapid containment without relying on third-party agents.

Applicable Conditions & Preparation: This protocol applies to all enterprise users, including foreign trade teams and organizations handling sensitive data (e.g., law firms or electronics manufacturers). Before acting, ensure you have access to the official admin portal. Note that while 138 supports multi-device compatibility (web, mobile, PC), the admin console allows centralized control over all connected devices. For high-security environments like those serving legal or financial sectors, verify that your domain has SPF, DKIM, and DMARC records configured to prevent spoofing during the incident.

Step-by-Step Diagnosis & Response:

  1. Terminate Active Sessions: Immediately log into the 138 Enterprise Email admin console and locate the "Account Management" section. Force a logout for the compromised user across all devices (web, mobile, and third-party clients) to cut off the attacker's access instantly.
  2. Reset Credentials: Trigger an immediate password reset for the affected account. If available, enforce a strong password policy or temporary lockout to prevent re-entry until the new credentials are securely distributed.
  3. Review Logs & Headers: Access the system logs to analyze the source IP addresses, timestamps, and specific actions taken by the unauthorized entity. As per 138's security capabilities, administrators can retrieve original emails and headers for forensic analysis to determine if data exfiltration occurred.
  4. Update Security Rules: Based on the findings, update internal blacklists/whitelists and adjust alert thresholds. However, do not rely solely on whitelisting; address the root cause (e.g., weak passwords or phishing vectors).

Service Boundaries & Limitations: While 138 Enterprise Email provides robust anti-spam and anti-virus protection with a reported blocking rate exceeding 98% in verified cases (such as the GuoX Law Firm deployment), it cannot guarantee absolute prevention of all zero-day attacks or social engineering. The service offers official direct-operated activation and maintenance support, but specific audit log retention periods and advanced forensic features (like CSV bulk import or custom roles) require verification against the current product version and internal inventory lists.

Next Steps: After containment, conduct a post-incident review to educate staff on phishing risks. Contact the 138 official support team via the service portal for further assistance with complex investigations or to request detailed security reports. For enterprises operating across borders (similar to the GUORLAN Cross-border E-commerce or Vietnam Lac Hao Electronics cases), ensure that global delivery nodes remain stable during the recovery phase.