Introduction
It's possible to specify multiple security mailboxes as targets of all reported threats In Hoxhunt, but it's not possible to select the target mailbox based on the reporting user's domain, country, department etc.
However, if you are using Microsoft Exchange Online, you can set up a mail flow rule that process the email based on the reporting user's AD attributes. For example, you could redirect reported threats to different security mailboxes based on user's country information.
Creating a mail flow rule (ETR)
NOTE: This is just an example. Ask your Exchange Administrator for assistance on which matching criteria and follow-up actions would best suit your needs.
Whenever Hoxhunt user reports a suspicious email as phishing, the email is forwarded to a designated security mailbox you have defined in Hoxhunt Admin Portal. The email is sent on behalf of the reporter, so the From address equals the reporter's email address.
In the following example, we create a simple mail flow rule that prepends the threat report email's subject line based on the user's city information in AD.
1. User has city attribute with value Redmond.
2. Create a mail flow rule that matches the user's city attribute value, and then define the appropriate follow-up action.
3. Once the email is reported via Hoxhunt button, the email is sent from the user's email address and the mail flow rule processes the email accordingly (prepending the Subject line in our example).
4. If needed, you can make additional mail flow rules to further process and redirect the email.