Skip to main content

Email Alert Configuration

Configure email notifications for security events with customizable templates, delivery schedules, and recipient management.

Universal Access

Email remains one of the most reliable notification channelsβ€”everyone has email, no additional tools required.


Why Use Email Alerts?​

BenefitDescription
Universal AccessNo additional tools or apps required
Flexible SchedulingImmediate alerts or scheduled digests
Rich FormattingHTML templates with tables and colors

Email Delivery Modes​

Immediate Alerts​

Emails sent within seconds of event detection.

Best For:

  • Malware detection and active threats
  • Authentication failures and account lockouts
  • Privilege escalation attempts
  • Critical agent health failures
Alert Fatigue

Use sparingly to avoid email overload. Reserve for critical events.


Configuring Email Alerts​

Step 1: Navigate to Email Settings​

Go to Configuration β†’ Notifications β†’ Email Alerts.

You'll see:

  • Existing email alert rules
  • SMTP configuration status
  • Delivery statistics

Dynamic Template Tags​

Use dynamic tags to include real-time event data:

TagDescription
{{EventType}}Event category
{{Severity}}Severity level
{{Timestamp}}Event time
{{Host}}Affected hostname
{{User}}Associated user
{{Message}}Event description
{{RiskScore}}Risk score value
{{EventId}}Unique identifier
{{MitreTactics}}ATT&CK tactics
{{SourceIP}}Source IP address

Template Customization​

Header & Branding​

ElementCustomization
Company LogoMax 200x60px
Primary ColorHex code
Footer TextDisclaimer, contact info
LinksSupport, unsubscribe

Managing Recipients​

Recipient Types​

TypeBest ForExample
IndividualSingle user alertssecurity-admin@example.com
Distribution ListTeam-widesoc-team@example.com
Role-BasedDynamic membership"Security Admin" role
On-Call Schedule24/7 coveragePagerDuty/Opsgenie integration
Dynamic Updates

Use role-based recipients for automatic updates when team membership changes.


Troubleshooting​

Emails Going to Spam​

SolutionImplementation
Configure SPFAdd DNS record
Set up DKIMConfigure signature
Add DMARCEnable policy
Safe senderAdd noreply@castellanai.com

Best Practices​

PracticeDescription
Severity-Based RoutingCritical β†’ immediate, Medium β†’ digest, Low β†’ summary
Configure SPF/DKIMPrevent spam classification
Include Action LinksDirect links to dashboard
Test RegularlyMonthly delivery tests
πŸ“ Email Configuration Checklist
  • Configure SMTP settings (if custom)
  • Set up SPF, DKIM, DMARC records
  • Create alert rules by severity
  • Customize email templates
  • Add dynamic tags
  • Configure recipients
  • Test delivery to all recipient types
  • Document escalation procedures

What's Next?​

GuideDescription
Notifications OverviewAll notification channels
Microsoft Teams IntegrationReal-time Teams alerts
Slack IntegrationReal-time Slack alerts