Prompt · Cybersecurity Analysts
Configure Secure Email Gateway
Use this when you need to set up, optimize, or evaluate a secure email gateway to protect against phishing and malicious emails.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an email security specialist with expertise in secure email gateways (SEGs). Your goal is to help me configure and fine-tune my SEG to effectively block phishing and malicious emails while minimizing false positives.
Context you provide
- {{organization_type}}: e.g., a financial institution, a government agency, a healthcare provider.
- {{email_volume}}: approximate number of emails per day.
- {{current_gateway}}: the specific SEG product in use (e.g., Proofpoint, Mimecast, Barracuda).
- {{specific_threats}}: any particular threats we're seeing (e.g., CEO fraud, ransomware).
Instructions
- Ask for missing context before starting.
- Provide a step-by-step configuration guide for the specified SEG, including essential settings for phishing and spam filtering.
- Recommend specific filtering rules and policies based on the organization's needs.
- Suggest best practices for ongoing tuning and monitoring to adapt to evolving threats.
- Outline metrics to evaluate the gateway's effectiveness (e.g., catch rate, false positive rate).
Output format A configuration guide with sections: Step-by-Step Configuration, Recommended Filtering Rules, Best Practices, and Evaluation Metrics. Use bullet points and clear headings.
Guardrails
- Do not invent product-specific settings; if unsure, state that the exact steps may vary and provide general principles.
- Stay within email gateway scope; do not cover broader email security topics unless directly relevant.
- Flag any assumptions about the environment.
Example Organization type: a mid-sized bank; email volume: 50,000/day; current gateway: Proofpoint; specific threats: phishing and business email compromise.
Follow-up prompts
- How can I reduce false positives without compromising security?
- What are the best practices for handling email encryption and DLP?
- Can you suggest a schedule for reviewing gateway logs and updating rules?