Skip to main content

Overview

When Ocean blocks an email it identifies as malicious or spam, you may need to release it if the email turns out to be legitimate. Ocean provides two ways to release blocked emails:
  1. Threat View
  2. Decision Center
Releasing an email marks it as safe and restores it to the recipient’s inbox. This action is logged for audit purposes.

Method 1: Release from Threat View

Use the Threat View when you have a single threat that needs to be investigated and released. The Threat View provides all the details you need to determine whether a threat is a false positive.

When to Use

  • A user reported a blocked email as a false positive
  • Your investigation of a threat reveals it’s legitimate
  • You need full context (sender details, email content, attachments, links) to make a decision

Steps

1

Navigate to Threats

Go to Threats in the main navigation to view all detected threats.
2

Select the Threat

Find and click on the threat you want to release. The threat details panel will open on the right side.
3

Click Release

In the threat details panel, click the Mark safe button.
Release button in threat view
4

Confirm the Action

A confirmation dialog will appear. Click Mark as Safe to release the email and mark it as safe.
Confirm release
5

Verify Release

After releasing, the threat will be marked as Safe with your name and timestamp recorded.

What Happens

When you release a threat from the Threat View:
  • All emails associated with the threat are restored to recipients’ inboxes
  • The threat is marked as Safe in the system
  • Your action is recorded with your name and timestamp
  • Future similar emails may benefit from this feedback

Method 2: Change Verdict in Decision Center

Use the Decision Center for broader email management capabilities beyond just releasing emails. It allows you to search across all emails, handle multiple emails at once, and change verdicts to Safe, Spam, or Malicious.

When to Use

  • You need to search for specific emails across your organization
  • You want to change verdicts for multiple emails in a batch operation
  • You need to change an email’s verdict to something other than Safe (e.g., Spam or Malicious)
  • You want to re-classify emails that were previously marked incorrectly

Steps

1

Navigate to Decision Center

Go to Decision Center in the main navigation.
Decision Center
2

Search for Emails

Use the search filters to find the email(s) you want to release. You can filter by:
  • Date range
  • Sender
  • Recipient
  • Subject
  • Current verdict
  • URLs/Files
3

Select Email(s)

Click on an email to view its details, or select multiple emails using the checkboxes for batch actions.
Select emails
4

Click Change Verdict

Click the Change Verdict button. This button appears in:
  • The email details drawer (for single emails)
  • The action bar (for batch operations)
Change verdict button
5

Select Safe

From the verdict options, select Safe to release the email(s).
Select safe verdict
6

Confirm

Confirm your selection. The system will process the verdict change and restore the email(s) to the inbox.
Select emails

Verdict Options

The Decision Center allows you to change emails to any of these verdicts:
VerdictAction TakenUse Case
SafeRestores email to inboxFalse positive - email is legitimate
SpamMoves email to spam folderUnwanted but not malicious
MaliciousKeeps email blocked/quarantinedConfirmed threat

Threat View vs Decision Center

FeatureThreat ViewDecision Center
ScopeSingle threatSingle or batch emails
Verdict OptionsSafe onlySafe, Spam, or Malicious
Best ForFalse positive threatsGranular email management
Search CapabilityBrowse threats listAdvanced search filters
Batch ActionsNot supportedSupported

Permissions Required

To release blocked emails, you need one of the following roles:
RoleThreat View ReleaseDecision Center Release
AdminYesYes
AnalystYesYes
Analyst Read-OnlyNoNo

Frequently Asked Questions

Email restoration typically happens within seconds. The recipient should see the email in their inbox shortly after you confirm the release.
Yes. If you accidentally release a malicious email, you can change its verdict back to Malicious using the Decision Center. This will re-quarantine or block the email.
Yes, your feedback helps Ocean’s AI learn. Marking emails as safe contributes to reducing false positives for similar emails in the future.
Yes. In the Threat View, releasing a threat releases all associated emails. In the Decision Center, you can select multiple emails and change their verdict in a single action.
Release actions are logged with your user ID and timestamp. Administrators and users with audit access can see who released emails and when.
Both methods support partial success. If some emails fail to release, the successful ones are still processed. Failed email IDs are reported so you can retry them individually.