Turn reported suspicious mail into Jira tickets
Opens a Jira ticket for each message your people report, and adds later reports of the same sender to the ticket already open.
What it does
The integration steps this workflow runs, in the order it first runs them.
- 1
GmailNew email trigger - 2
GmailList emails - 3
JiraSearch issues
- 4
JiraAdd comment
- 5
JiraCreate issue
- 6
GmailAdd label to message
How it works
Everything the template sets up, and what to fill in before the first run.
People spot suspicious mail long before anything else does, and the trouble is usually what happens next: it sits in someone's inbox, or in a shared mailbox nobody owns. This workflow turns each reported message into a ticket in your Jira project, so it lands in the queue your responders already work from.
Nothing in it makes a judgement. Every line of the ticket is copied from the message: the sender address, the name shown on the message, whether that address is on one of your own domains, the subject as it arrived, the hosts its links point to, and the Gmail message id. There is no rating, no score and no conclusion anywhere in the output, because with no way to check an address against anything, a conclusion would be invention. Reading the evidence is left to the person the ticket is assigned to.
Two things it does do for you:
- It checks the name shown on the message, and the subject, against the names you list in 'impersonatedNames' - your company, your finance team, whoever gets used against you - and records any that appear while the address itself is not on one of your own domains. That is an observation about the two fields, nothing more. - It records only the host part of each link, never the whole address. The rest of a link often carries a code identifying the person it was sent to, and a ticket is read by people who did not receive the message.
One ticket per sender, not per report. Each ticket's title carries the sender address inside a bracketed marker, and before opening a new one the workflow searches your project for that exact marker. When it finds it, the report is added to that ticket as a comment instead. Twenty people forwarding the same message get one ticket and nineteen comments.
The message is labelled only after its ticket or comment has been written, and the Gmail search excludes that label. A run that dies half-way therefore repeats a report rather than losing it: a duplicate is something a person can see and close, and a report that quietly vanished is not.
To set it up, put the Gmail search that finds reported mail into the 'reportSearch' step (for example label:reported), the key of your Jira project into 'jiraProjectKey', your own email domains into 'ourDomains', and the names that get used against you into 'impersonatedNames'. 'triagedLabel', 'issueType' and 'maxReportsPerRun' have working defaults. At most ten reports a run and at most eight link hosts a message, both editable on their steps. Naming a sender on the trigger step narrows what wakes it; left empty, any new mail wakes it and the search decides what counts as a report.
Start from a workflow that already works.
Add "Turn reported suspicious mail into Jira tickets" to your workspace, connect its apps, and make it yours. No credit card required.
Free plan available · No credit card required
