Scan Zendesk tickets for phishing links every 15 minutes

By General Input

Every 15 minutes we check new support tickets for unsafe links, flag the risky ones on the ticket, and alert your security channel in Slack.

Integrations

  • IPQualityScore
  • Zendesk
  • Slack Bot

Type

Agentic Task

Categories

  • Customer Support
  • Operations

Every 15 minutes, on a cron trigger, check our Zendesk support queue for suspicious links so that agents never click a phishing page a customer forwarded in.

Start with the Zendesk List Tickets operation to pick up tickets created since the last run, and keep track of the timestamp you stop at so the next run resumes from there without reprocessing the same tickets. For each new ticket, use Show Ticket to read the ticket details and List Ticket Comments to read the full message bodies, including the original request and any replies that came after it.

Extract every URL and bare domain you find in those message bodies. Before scanning anything, drop the links that are on an allowlist: our own domains, our help center, and well known safe senders such as major cloud, payment, and calendar providers. The goal is that agents are only warned about genuinely unusual links and never about ordinary business links. Deduplicate the remaining links across the whole batch so the same URL is only scanned once, since each scan consumes IPQualityScore credits.

Scan each remaining link with the IPQualityScore Malicious URL Scanner, which checks for phishing, malware, and suspicious domain reputation. The target URL must be URL-encoded before it is placed in the path segment, otherwise the scan will not resolve correctly. IPQualityScore returns errors as HTTP 200 with success set to false, so always branch on the success field rather than the HTTP status code. If a scan fails or the account is out of credits, treat that link as unknown and report it as unknown. A failed scan must never be read as a clean verdict.

Treat a link as unsafe when the scanner reports phishing, malware, or suspicious activity, or when the risk score is 75 or above. Scores of 90 or above are high risk and should be called out as such in the note.

When a ticket contains at least one unsafe link, use Zendesk Update Ticket to add an internal note that names the exact unsafe URL, its risk score, and what the scanner flagged, whether that was phishing, malware, or poor domain reputation. Keep the note short and factual and tell the agent not to click the link. In the same update, add a suspicious-link tag and raise the priority. Preserve the ticket's existing tags rather than overwriting the whole tag array, and only ever raise the priority, never lower it.

Then post a message to our security channel in Slack with a direct link to the ticket, the ticket subject, the unsafe URL, and its risk score, so the security team can follow up. Send one message per affected ticket rather than one per link.

Stay silent when every link in the batch is clean. Do not post to Slack, do not add internal notes, and do not tag or reprioritize tickets when there is nothing to report.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them