Automated Barracuda Quarantine Triage
Every hour, WebRun signs into Barracuda, reads the messages held in quarantine since the last check, compares each sender against your allow and block lists and past traffic, posts a short release queue to Slack for an admin, and tells the affected team in Microsoft Teams.
How do I catch legitimate email stuck in quarantine faster?
Every hour WebRun signs into Barracuda, reads the messages sitting in quarantine, and picks out the ones that look like genuine business mail from known senders. It posts a short release queue to Slack and tells the affected team in Microsoft Teams. WebRun proposes: the admin releases.
- A supplier invoice does not sit stuck in quarantine all day
- Every proposed release names why it looks legitimate
- Releases stay an admin decision, always
Built for IT admins · security teams · managed service providers · operations managers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.barracuda.comin a real browser with your saved login - no setup, no API keys. -
1
Barracuda Networks - review quarantined messages
WebRun opens Barracuda Networks to review quarantined messages. - Sign into Barracuda and open the messages quarantined since the last run
- Record the sender, the recipient, the subject, and the reason each was held
- Compare each sender against your allow and block lists and against mail you have received before, and mark the likely false positives
Done when Every newly quarantined message is marked as probable spam or probable false positive.
-
2
Slack - post the release queue
WebRun opens Slack to post the release queue. - Post the probable false positives to your IT channel as a release queue
- Give each line the sender, the recipient, the subject, and why it looks legitimate
- Leave every release to the admin. WebRun never releases, deletes, or allowlists a message itself
Done when The IT channel holds this hour's proposed releases, none of them actioned.
-
3
Microsoft Teams - tell the affected team
WebRun opens Microsoft Teams to tell the affected team. - Post a short note to the channel of any team with mail waiting on a decision
- Name the sender and the subject so the recipient can confirm they were expecting it
- Skip the post entirely on hours with nothing to review
Done when Teams waiting on a held message know it is queued for review.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it release messages from quarantine on its own?
No. WebRun proposes and the admin releases. It never releases a message, deletes one, or changes an allow or block policy, so a bad call cannot let a threat through.
How does it judge a message as legitimate?
It weighs the sender against your allow and block lists, your history of mail from that domain, and the reason the message was held, then labels only clear cases as probable false positives.
Does it open or forward the quarantined mail?
No. It reads the sender, recipient, subject, and block reason from the quarantine list. It does not open attachments, follow links, or forward held messages anywhere.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.