Lately, we've been hit with some whaling attempts that have gotten past Mimecast. The attempts are sloppy enough to slip right past impersonation detection as they don't include anything in their message that would trigger the filter. They didn't disguise the address or attempt to make it look like our domain. The envelope, reply-to, and header

We are a new customer to Mimecast and have just turned on the Digest (That was the first obstacle for our company) I am really wanting to turn on the URLProtection (I have it on for my team) for an added layer of protection. Has anyone had a chance to write up some documentation that they did for their users. I am looking for a document to