| CPC H04L 63/1441 (2013.01) [H04L 51/08 (2013.01); H04L 51/21 (2022.05); H04L 63/1433 (2013.01); H04L 63/20 (2013.01)] | 20 Claims |

|
1. A method comprising:
identifying, by one or more servers, that a message reported by a user as suspicious is a malicious message;
converting, by the one or more servers, the malicious message to a defanged message that has benign elements;
communicating, by the one or more servers, the defanged message to a plurality of users other than the user who received the message;
determining, by the one or more servers, an impact score for the user based at least on one or more interactions with at least the benign elements of the defanged message by the plurality of users; and
providing, by the one or more servers, a status to the user who reported the suspicious message based at least on the impact score.
|