---
title: How Does Scoring Work for KillPhish report add-in?
description: This guide outlines the criteria, description, and score reduction calculated for the KillPhish reporting tool.
---

[Skip to content](https://support.hooksecurity.co/how-does-scoring-work-for-killphish-report-add-in#main-content)

English

Show submenu for translations

[Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new?hsLang=en) [Customer Portal](https://support.hooksecurity.co/tickets-view?hsLang=en)

[![Hook\_Logo (3)](https://support.hooksecurity.co/hs-fs/hubfs/Hook_Logo%20(3).png?width=150&height=113&name=Hook_Logo%20(3).png)](https://www.hooksecurity.co/welcome)

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)

Open main navigation

Close main navigation

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)
- English
  
  Show submenu for translations
- [Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new)
- [Customer Portal](https://support.hooksecurity.co/tickets-view)
- [Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

[Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.hooksecurity.co/?hsLang=en)
2. [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en)
3. [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)

# How Does Scoring Work for KillPhish report add-in?

## This guide outlines the criteria, description, and score reduction calculated for the KillPhish reporting tool.

The Microsoft KillPhish add-in will score an email if the Advanced Threat Protection (ATP) feature is turned on. Based on the score, the email will be marked as "Low Risk" for scores \>= 95, "Medium Risk" for scores between 60 and 95, and "High Risk" for scores \<= 60.

This table shows how the email score is calculated.

![](https://support.hooksecurity.co/hs-fs/hubfs/image-png-Jan-17-2024-05-22-41-0932-PM.png?width=688&height=368&name=image-png-Jan-17-2024-05-22-41-0932-PM.png)

If you own the Security Inbox feature, you can connect it to the KillPhish add-in and create your own blocklists and safelists for links and senders. These blocklists can help make ATP more accurate for the add-in.

Note: KillPhish's Advanced Threat Protection (ATP) scoring is **not** capable of detecting every social engineering/phishing threat in emails. You should use the other tools that Portal provides to educate your users about the various threats posed by phishing and social engineering, and how to detect these attacks. It is capable of detecting if an email passes SPF check, scores based on certain words/phrases that are considered high risk, and decreases an email's score if it contains certain high risk file attachments (such as .exe or .html files). Portal gives users the ability to turn off ATP on the Reporting Settings page.

 

- [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en#main-content)

    - [General](https://support.hooksecurity.co/getting-started?hsLang=en#general)
    - [General Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#general-safelisting)
    - [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)
    - [GSuite Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#gsuite-safelisting)
    - [Firewall/Spam Filter Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#firewall-spam-filter-safelisting)
    - [Creating Groups/Adding Targets](https://support.hooksecurity.co/getting-started?hsLang=en#creating-groups-adding-targets)
    - [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)
    - [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)
    - [Platform Settings](https://support.hooksecurity.co/getting-started?hsLang=en#platform-settings)
- [Hook Academy](https://support.hooksecurity.co/hook-academy?hsLang=en#main-content)

    - [Campaign Ideas](https://support.hooksecurity.co/hook-academy?hsLang=en#campaign-ideas)
    - [Industry Specific Campaigns](https://support.hooksecurity.co/hook-academy?hsLang=en#industry-specific-campaigns)
    - [Course Reviews](https://support.hooksecurity.co/hook-academy?hsLang=en#course-reviews)
    - [Mastering Reporting](https://support.hooksecurity.co/hook-academy?hsLang=en#mastering-reporting)
    - [Becoming Compliant](https://support.hooksecurity.co/hook-academy?hsLang=en#becoming-compliant)
    - [Suggest a Hook Academy Topic](https://support.hooksecurity.co/hook-academy?hsLang=en#suggest-a-hook-academy-topic)
- [Tests/Campaigns](https://support.hooksecurity.co/tests-campaigns?hsLang=en#main-content)

    - [Reseller Only](https://support.hooksecurity.co/tests-campaigns?hsLang=en#reseller-only)
- [School](https://support.hooksecurity.co/school?hsLang=en#main-content)

    - [3rd Party Integrations](https://support.hooksecurity.co/school?hsLang=en#3rd-party-integrations)
    - [Troubleshooting](https://support.hooksecurity.co/school?hsLang=en#troubleshooting)
    - [Branding](https://support.hooksecurity.co/school?hsLang=en#branding)
    - [Course](https://support.hooksecurity.co/school?hsLang=en#course)
    - [Students](https://support.hooksecurity.co/school?hsLang=en#students)
    - [Automations](https://support.hooksecurity.co/school?hsLang=en#automations)
- [Reports](https://support.hooksecurity.co/reports?hsLang=en#main-content)

    - [Generate Reports](https://support.hooksecurity.co/reports?hsLang=en#generate-reports)
- [FAQs](https://support.hooksecurity.co/faqs?hsLang=en#main-content)

    - [Troubleshooting](https://support.hooksecurity.co/faqs?hsLang=en#troubleshooting)
    - [Campaign of the Month](https://support.hooksecurity.co/faqs?hsLang=en#campaign-of-the-month)
- [Reseller Guide](https://support.hooksecurity.co/reseller-guide?hsLang=en)
- [Hook Security Updates](https://support.hooksecurity.co/hook-security-updates?hsLang=en)
- [Onboarding Guides](https://support.hooksecurity.co/onboarding-guides?hsLang=en)
- [Managed Services](https://support.hooksecurity.co/managed-services?hsLang=en)

- [Default HubSpot Blog](https://hooksecurity-6535385.hs-sites.com/blog)

[![Newsletter\_Logo-08](https://support.hooksecurity.co/hs-fs/hubfs/Newsletter_Logo-08.png?width=250&height=59&name=Newsletter_Logo-08.png "Newsletter_Logo-08")](http://hooksecurity.co)

Proudly Headquartered in Lakeland, Floirda

<https://www.linkedin.com/company/hooksecurity>

Copyright © 2026, Hook Security Inc.