Proto for all phishing alerts with common payload. Supported types are any of the following:
- User reported phishing
- User reported spam spike
- Suspicious message reported
- Phishing reclassification
- Malware reclassification
- Gmail potential employee spoofing
JSON representation |
---|
{ "domainId": { object ( |
Fields | |
---|---|
domainId |
The domain ID. |
maliciousEntity |
The entity whose actions triggered a Gmail phishing alert. |
messages[] |
The list of messages contained by this alert. |
isInternal |
If |
systemActionType |
System actions on the messages. |