Skip to content
Avanet

Operate Sophos Email reports and monitoring

The Sophos Email dashboard provides a quick operational view; reports provide the verifiable detail. This workflow explains how to select Gateway and Mailflow data correctly, trace anomalies to a message or user, and create repeatable reports. It is intended for administrators with reporting permission in the correct Sophos Fusion (formerly Sophos Central) tenant.

Reports don’t change policies or licenses and don’t perform remediation. They support the owners of those tasks. Make changes through the separate workflows for Data Control, Time-of-Click URL protection, Post-Delivery Protection, and license usage.

Prepare access and the investigation scope

You need reporting permissions and the relevant license for feature-specific reports. Before analyzing data, record the tenant, question, expected domain or user, direction, date range, and time zone. Send personal report data and exports only to authorized recipients.

If domains use both Sophos Gateway and Sophos Mailflow, select the correct dataset in the dashboard and reports. Gateway, Mailflow, and both are not interchangeable filters: they represent different processing paths. For an empty or unexpected report, first verify the tenant, Type, date range, and effective license.

Use the dashboard as the starting point

At My Products > Email Security > Dashboard, set the processing mode and date range first. All widgets respond to that selection. The default is 30 days; the maximum is 30 days, or 90 days with Sophos Email Plus. Gateway and Mailflow domains produce separate panels with the same message categories.

The Inbound Statistics and Outbound Statistics ribbons open details; Mailboxes Licensed opens the license summary. Widgets cover Inbound Activity Summary, Outbound Activity Summary, Intelix Threat Summary, TLS Encryption Summary, Post Delivery Summary, Data Control, and At Risk Users. A category or See Report opens the relevant report with dashboard context. The alert indicator opens Alerts, filtered to Sophos Email.

The dashboard PDF from Export includes the filters in effect and no more than 30 days, or 90 days with Email Plus. Record the mode, date range, and time zone with the export.

Choose the correct report and range

TaskReport and pathRange and boundary
Message and TLS volumeReports > Email Security > Message Summary30 days by default, up to 365 days
DLP violationsReports > Email Security > Data control summaryup to 365 days; direction, category, and action
Automatic remediation and clawbackReports > Email Security > Post delivery summaryup to 365 days; only with post-delivery protection enabled
Clicked URLsReports > Email Security > Time of Click Summary30 days, or 90 with Email Plus; unavailable in EMS mode
Users at riskReports > Email Security > At risk users30 days, or 90 with Email Plus; license-dependent signals
Reported misclassificationsReports > Email Security > SophosLabs Analysis Reportup to 365 days in the report; exports are limited to 90 days
Intelix file analysisReports > Intelix Threat Summaryup to 365 days; in-progress analysis isn’t final
License scansReports > Email Security > License Usage Summaryup to 365 days; values come from periodic scans

A 365-day report doesn’t mean every drill-down also covers 365 days. In particular, links from Message Summary to Message History are available only for 30 days, or 90 days with Sophos Email Plus. Realtime blocked can’t open Message History because these messages are blocked during the SMTP command and little detail is available.

Investigate messages, TLS, and policy events

In Message Summary, set Type, date range, and Direction, then use Summarise by with Category or TLS Encryption. Toggle categories in the legend and graph; the table and linked counts must reflect the same filter context. A linked count opens Message History for supported categories and ranges. Match date, sender, recipient, and message ID before assessing an individual case.

TLS has a different boundary by mode: in Gateway mode it describes the connection between Sophos Email and the external sender or recipient; in Mailflow mode it describes the connector between Sophos Email and Microsoft 365. Don’t compare Unencrypted, TLS v1.2, and TLS v1.3 without preserving the mode.

In Data control summary, choose Type, date range, Direction, Category, and Action. Results identify policy violations but don’t replace inspection of the effective Data Control policy. Create Phish Threat campaign is available only with Sophos Phish Threat; review the preselected users captured in the range before starting a campaign.

Post delivery summary contains messages from Auto search and remediate or On demand clawback, and appears only when post-delivery protection is enabled. It has no direction filter because every entry is inbound. Details can show successful delivery, release, or clawback, but configuration and remediation remain part of the post-delivery workflow.

Correlate URL risk and users at risk

Time of Click Summary separates Total Clicks, Clicks Allowed, Clicks Warned, and Clicks Blocked. A high count proves neither compromise nor misconfiguration. Select a value in Clicks Warned or Clicks Blocked to pass its category and time period to At Risk Users.

In At Risk Users, the Risk index combines Time-of-Click and impersonation signals. Select the index to open the user’s report and a subject to open message details. These users are prioritization signals, not an attribution of fault. Direct Phish Threat training requires a Sophos Phish Threat license; verify the audience and range before launch.

Interpret SophosLabs and Intelix verdicts correctly

The SophosLabs Analysis Report separates false negatives submitted as Reported threat from false positives submitted as Reported clean. Sophos detected is the initial classification; SophosLabs analyzed is the later analysis verdict. Investigate differences rather than automatically treating them as policy failures. Advanced Search combines sender, reporter, source, subject, verdict, and reporting date with logical AND.

Important: Analysis pending is neither a clean nor a malicious final verdict. Keep the case open until SophosLabs completes analysis; don’t allow a sender or weaken a policy based on this intermediate state.

Intelix Threat Summary shows clean, likely clean, suspicious, and malicious. For a completed verdict, select the subject to inspect Summary, Threat prevalence, Static analysis, and Dynamic analysis. The subject isn’t selectable while analysis is in progress. Intelix processing errors can quarantine a message; the report alone doesn’t authorize release.

Allow and block actions in the SophosLabs report are context-specific: allow under Reported clean, block under Reported threat. Check scope and record a reason before domain or IP actions. Never broadly block a shared Microsoft 365 IP based on one result.

Reconcile license usage

License Usage Summary shows periodic scans, not a continuously updated real-time counter. Select a scan by date and local time, use graph sliders to focus if needed, and open a mailbox in Mailboxes. The Mailboxes Licensed number can differ from a report value when a different range or scan is selected.

For an auditable check, record scan time, report range, searched mailbox, and export. Don’t make a capacity or term decision from one graph point alone.

Schedule or export a report

After applying all business filters, select Save as Custom Report. On Report Template, enter Template Name, enable Schedule, set Report Date Range, choose Report Frequency as Daily, Weekly, or Monthly, set Ends On or Until I cancel, select Report Format and Report Notification and Delivery method, then use Save Report Template. Monthly is available only when the report covers at least 30 days.

Most reports described here support CSV or PDF. Message History and Rejection Log are CSV-only. Prefer a link for personal data because access requires Sophos Fusion credentials. Attachments over 9.5 MB are automatically sent as links. Scheduled reports go to the address in Account Details and optionally to other Sophos Fusion administrators; recipients are notified if generation fails.

Filters other than the current date range carry into the template and can’t be changed after report generation. Use Generated Reports to verify generated reports and actual delivery. A generated report contains at most 50,000 records and is deleted from Generated Reports after 90 days, so download required results in time under the applicable retention policy. A manual Export includes all current filters; each report’s format and range restrictions still apply.

Validate results and troubleshoot

Don’t validate only one card. Reconcile graph, statistics ribbon, table, and drill-down using the same Type, date range, direction, and time zone. Check samples from linked counts against date, category, recipient, and message ID. For a schedule, have an authorized recipient confirm delivery or authenticated link access.

  • No data: check the tenant, Gateway/Mailflow or Type, range, direction, and empty or conflicting filters.
  • Report or action missing: check license, product mode, and reporting permission; Time of Click Summary is unavailable in EMS mode.
  • Counts differ: compare filter context, local time, scan time, and report run; dashboard, license scan, and detailed report can use different windows.
  • No drill-down: account for the 30/90-day limit and the non-drillable Realtime blocked category.
  • Intelix or SophosLabs verdict missing: wait for scanning or analysis to complete and keep Analysis pending open.
  • Scheduled report missing: check Schedule, end date, the recipient in Account Details, generation failure, spam filtering, and conversion of a large attachment to a link.

For escalation, preserve tenant ID, report name, link-free navigation path, Type, range and time zone, filters, license/mode, generation time, expected and visible counts, and a few message IDs. Minimize exports according to privacy requirements. Keep protection policies active while investigating; a reporting discrepancy isn’t a reason to disable controls.