Use the following tokens to include variables in notifications and stamps:

Table 1. Tokens and Variables

Token

Variable

%SENDER%

Message sender

%RCPTS%

Message recipients

%SUBJECT%

Message subject

%DATE&TIME%

Date and time of incident

%MAILID%

Mail ID

%RULENAME%

Name of the rule that contained the triggered filter

%RULETYPE%

The type of rule: Content Filter, Message Size Filter, and others

%DETECTED%

Current filter scan result in other task

%FILENAME%

Name(s) of file(s) that were affected by the rule

%DEF_CHARSET%

Default character set of the notification message

%MSG_SIZE%

Total size of the message and all attachments

%ATTACH_SIZE%

Total size of the attachment(s) that triggered the rule

%ATTACH_COUNT%

Number of attachments that triggered the rule

%TACTION%

Terminal action taken by Hosted Email Security

%ACTION%

All other (non-terminal) actions taken by Hosted Email Security

%VIRUSNAME%

Name of any malware detected

This token will be empty if the message did not trigger a malware action.

%VIRUSACTION%

Action taken on any malware detected in the message

This token will be empty if the message did not trigger a malware action.