Skip to content
POWR Help Center home
InboxAsk a human

How to handle Auto Dephish Notifications

What are Auto Dephish Notifications?

Auto Dephish Notifications look like this:

FIX: BROKEN_ATTACHMENT (original: https://help.powr.io/hc/article_attachments/360057065773/mceclip0.png)

This is an automated alert when a user got flagged for phishing and they have an active subscription. 

The alerts used to come into Slack. They now also come into support as a ticket. 

Support has to deal with these. If we ignore the notification, we lose the user without having given them the benefit of the doubt. This means a sad User and less $$$ for POWr 😭 Don't let that happen!

What do I need to do about Auto Dephish Notifications?

Let's go through this step by step:

  1. Copy the email address from the alert.
  2. Look up the user in TSH.
  3. Check the "Notes" tab to see which of their forms got flagged for phishing.
  4. In the "Apps" tab, select the form which got flagged. 
  5. Review the content in the form (and perhaps also the Auto Responder, if there is one).
  6. Determine if the user is intentionally phishing for information or if the user is requesting a password or login details for a non-malicious reason.

 

This is clearly a phishing form:

FIX: BROKEN_ATTACHMENT (original: https://help.powr.io/hc/article_attachments/360057066333/mceclip1.png)

This is not technically a phishing form:

FIX: BROKEN_ATTACHMENT (original: https://help.powr.io/hc/article_attachments/360057066873/mceclip2.png)

If the user is definitely a phishing user...

  1. Cancel the user's active subscription (choose "Phishing" as the reason)
  2. Completely dephish the account using the "Dephish" button in TSH. 
  3. Add an internal note to the ticket with a summary of what you did and why you did it. Also add an emoji reaction to the Slack message so we know someone took care of it ✅

If the user is most likely not a phishing user...

  1. In TSH, click "Reactivate account"
  2. Search Zendesk for the user's email to see if the user has already contacted us about their deactivated account. If yes, reply to the existing ticket. If no, create a new ticket and remember to tag it with "proactive" (see Creating a new ticket in Zendesk ).
  3. Use the "Phishing User With Upgrade - Not phishing, no permanent ban" macro.
  4. Add an internal note to the ticket with a summary of what you did and why you did it.Also add an emoji reaction to the Slack message so we know someone took care of it ✅

Important notes:

  1. If the user writes back and requests to have the form undeleted, remove the password field from the form and reactivate the form. If you don't remove the password field, their account will immediately get flagged and deactivated again. If the user is someone we know well (say, they've been a good customer for several years), you can also remove their form from the phishing list via the button in the "Notes" tab. 
  2. If the user re-adds the password field, we will get another alert in Slack - give the user a second warning. 
  3. If the user is not malicious but just does not get it and keeps creating new forms with password fields, fire the user, refund them and cancel their upgrade (like we did with Gisele in screenshot above).