Configure Lumu Spambox for Proofpoint

Lumu Email Intelligence and Proofpoint

In this document, you will learn how to configure Proofpoint Enterprise policies to forward your emails to Lumu for compromise assessment. Lumu Email Intelligence is a unique threat analysis tool that runs advanced correlations between your spam, known indicators of compromise (IoCs), and network traffic.

Notes
Learn more about how Lumu Email Intelligence helps you understand who is targeting your organization, how they are doing it, and how successful they are in our documentation.

Requirements

  • You must have Proofpoint Enterprise admin permissions to access the Spam Detection Module.

Proofpoint Setup

1. Lumu assigns a unique email address to your organization. You can find the email address assigned to your organization by going to the Lumu Portal and navigating to Lumu Email under the Intelligence sub-menu. 


2. Sign in to Proofpoint using your admin account, and then navigate to Email Protection > Spam Detection > Policies > Rules. Select the Policy and under the Rules section, select the spam rule and click “Edit”.


3. Under the Disposition section, select the checkbox titled “Send a copy to destination”, then select the “Copy original message” checkbox and add the Lumu email address provided to your company during step 1 in the “New recipient(s)” field.

Notes
You can use the default SMTP profile or any other you may have created.


Notes
Repeat steps 2 and 3 for all the policies you want to have the emails forwarded to Lumu. We recommend forwarding to Lumu at least the emails filtered by Phishing, Malware, and Bulk Email policies.

For further details about the Spam Detection settings, consult the Proofpoint documentation