A 'Reporter domain' is the source domain from which PhishTool receives reported phishing emails, via an In-tray source. Specifically, they are the domain(s) which your end-users have their mailbox(es) hosted on.

For example, if your corporate domain is acme.com and your end-users have mailboxes with email addresses like john.smith@acme.com, and you wished to ingest emails from these users via a mailbox integration, then acme.com must be listed in the 'Reporter domains' table, before any emails from this reporter domain will be accepted by PhishTool.

The 'Reporter domains' table can be accessed via 'Workspace Settings' under 'In-tray'.

Reporter Domain Quotas

Your PhishTool Enterprise workspace will have a quota of 'Reporter domains' available. For example, your workspace may have 3 'Reporter domains' available. This means up to 3 domains can be added to this table. It is possible to increase your workspace's 'Report domain' quota by clicking the 'Increase your reporter domain quota' option, above the table in the 'Reporter domains' settings screen.

If you wish to add a new 'Reporter domain' (without increasing your quota), you can remove an existing 'Reporter domain' from the table (which will free up a 'Reporter domain' space) and then add the new domain.

Reporter Domain Notifications

If your PhishTool workspace receives reported phishing emails from a 'Reporter domain' that has not been configured in the 'Reporter domains' table, then PhishTool will automatically generate a notification, which can be seen in the 'Notifications' drop-down in the PhishTool main menu.

Restricting In-tray Source Reporter Domains

Each In-tray source type (Mailbox integration, Phish Report Button (PRB) and API) can by optionally configured to restrict the 'Reporter domains' it will accept reported phishing emails from.

This is done by selecting the 'Reporter domain' from a drop down in the 'Domains' setting when configuring an In-tray source instance. This can be done at the time an In-tray source is first configured, or later on. This will then permit only the configured 'Reporter domain' in the In-tray source configuration. Any emails reported via that In-tray source from any other 'Reporter domain' (not configured), will be ignored by PhishTool. Conversely, if no 'Reporter domains' are specified for an In-tray source, then any email reported by an end-user with an email address domain listed in the 'Reporter domains' table, will be received by that In-tray source.

Apex Domains

When configuring a 'Reporter domain', only apex domains are accepted. For example, if acme.com is a configured 'Reporter domain', then any subdomains on acme.com will be automatically accepted by PhishTool.

This means if john.smith@acme.com and jane.doe@mail.acme.com report emails via an In-tray source into PhishTool, then both will be accepted, as the 'Reporter domain' acme.com was configured in the 'Reporter domains' table.