Skip to content

Email Intelligence guide

Email Intelligence adds mail-observed domain signals to Have I Been Squatted. Connected providers send normalized email telemetry facts, which are matched against monitored domains and lookup results. The feature is designed for earlier domain discovery, especially when abusive sender domains appear in mail before they appear in registration, certificate, or passive DNS workflows.

Email Intelligence currently supports Microsoft 365 and Google Workspace ingestion. To quarantine mail from lookalike domains in Exchange Online, use the Microsoft 365 Quarantine connector with a rule; see Quarantine senders.

Microsoft 365 Email Intelligence integration

  • Email telemetry ingestion: Poll the best available Microsoft 365 source or Google Workspace Gmail audit logs for domain-level mail facts
  • Provider attribution: Mark lookup results as discovered through email telemetry, including provider and evidence source
  • Dashboard analysis: Review recent message, URL-domain, and attachment-metadata observations alongside email-sourced lookup results
  • Observation review: Inspect messages, URL domains, attachment metadata, and response activity in focused views

Email Intelligence stores privacy-bounded facts rather than raw mailbox data. Stored events include provider, observation time, event type, direction, sender domains, recipient domains, URL domains, attachment metadata, matched monitored domains, and hashed provider identifiers.

The ingestion pipeline intentionally excludes raw provider payloads, message subjects, local parts, full email addresses, message bodies, and full uniform resource locators (URLs). Message and event identifiers are hashed before storage.

Provider-specific behavior:

  • Microsoft 365 Advanced Hunting: Reads message, URL, and attachment metadata. URL observations store the domain and provider-reported location rather than the full URL. Attachment observations store available file type, size, hashes, and threat-detection metadata rather than filenames or file contents.
  • Microsoft 365 Exchange Message Trace: Reads message-level transport metadata. It stores hashed trace and Message-ID values plus the SMTP MAIL FROM and recipient domains. It does not create URL, attachment, or threat observations. Historical observations remain visible if an integration changes source.
  • Google Workspace: Reads Google Workspace Admin software development kit (SDK) Reports application programming interface (API) Gmail delivery audit events. Candidate domains can come from sender and header fields, plus link-domain audit fields when Google exposes them, but stored events remain domain-level facts.

Open Connectors > Microsoft 365 Email Intelligence.

  • Email ingestion: Uses Defender Advanced Hunting when available. It falls back to Exchange Message Trace only when the mandatory EmailEvents query explicitly reports a missing table or an unprovisioned account. Requires ThreatHunting.Read.All and ExchangeMessageTrace.Read.All.

Choose Connect tenant or Reauthorize, then complete the Microsoft administrator consent flow.

Existing integrations continue to use Advanced Hunting without the new Message Trace consent. Reauthorize them to make fallback available. Exchange Message Trace also requires the tenant administrator to provision Microsoft’s documented first-party service principal. This is a separate tenant prerequisite. Have I Been Squatted does not request Application.ReadWrite.All or provision the service principal.

Open Connectors > Google Workspace Intelligence.

Enable Gmail audit logs, then connect with a Google Workspace administrator account. The Open Authorization (OAuth) flow requests Admin SDK Reports audit access for Gmail delivery events. Reconnect if the integration status indicates permission loss, no usable refresh token, or a source authorization error.

Google Workspace ingestion contributes email-observed domains and message observations.

Email ingestion proposes candidate domains from provider telemetry. Have I Been Squatted then applies conservative matching before adding email attribution to lookup results:

  1. Monitored domains and their subdomains are not treated as suspicious candidates.
  2. Existing lookup results are updated first, so email evidence is attached to the current result when possible.
  3. New candidates are matched against monitored domains by recipient-domain ownership or a unique close-domain match.
  4. Ambiguous matches are skipped instead of being assigned to the wrong monitored domain.
  5. A completed lookup must exist for the monitored domain before new email-sourced results can be inserted.

When a candidate is accepted, the result appears alongside normal lookup results with an email source marker.

Lookup result with Microsoft Defender email source

The result can still use the normal rules engine, tags, alerts, exports, and investigation workflows. The main difference is provenance: the domain was observed in connected mail telemetry.

The email namespace queries persisted Email Intelligence events directly. This differs from domain.metadata.sources.*, which describes the provenance of a domain lookup result. Conditions within Email must match one event; separate message, URL, and attachment rows are not joined automatically.

See Email signals for the field catalog and rules across namespaces for execution windows and preview behavior.

Open Email Intelligence from the application sidebar to review the operational view.

The Overview summarizes the last 14 days:

  • Message observations: Normalized email message events ingested from connected providers
  • URL observations: Microsoft 365 URL-domain observations linked to message telemetry
  • Attachment observations: Microsoft 365 attachment metadata linked to message telemetry

The Overview uses the same 60-day message-activity timeline as the focused views, alongside compact URL and file summaries and recent email-observed lookup results. Selecting a day opens the corresponding Emails view. Email-sourced lookup rows link back to the relevant monitored-domain lookup results.

Dedicated Emails, URLs, and Files views separate message activity from Microsoft 365 URL-domain and attachment-metadata observations. Each view includes 14-day summary metrics, a 60-day activity timeline, focused characteristics, and privacy-bounded rows. Google Workspace currently contributes message telemetry only.

The Emails view shows 14-day message metrics and breakdowns, followed by normalized message facts and historical Watchdog quarantine pushes for a selected Coordinated Universal Time (UTC) day.

Email Intelligence Emails view

Each row includes the observation time, event type, provider, direction, available sender and recipient domains, hashed message correlation identifier, linked monitored domains, and response outcome. URL and attachment observations remain available in their dedicated views.

Depending on the event type, observation details include:

  • Message: Sender and recipient domains
  • Quarantine push: The action and result of a sender block from the retired Watchdog

Use this view when validating message ingestion, reviewing sender and recipient context, or reviewing past Watchdog activity.

Email Intelligence observes mail; it doesn’t block it. To quarantine mail from lookalike domains, connect the Microsoft 365 Quarantine connector and add the Quarantine in Microsoft 365 response to a rule. For each alert, the response adds an expiring sender block for the cited lookalike domains to the Exchange Online Tenant Allow/Block List, and Exchange Online quarantines their mail.

The connector uses its own Microsoft Entra application, separate from Email Intelligence, and requires the network enforcement add-on.

Watchdog was a Microsoft 365 Email Intelligence option that added sender blocks using a built-in heuristic. It is retired. The Emails view keeps its past quarantine pushes. Blocks it created expired 30 days after they were added.

To reproduce the Watchdog heuristic, create a Domain rule with the Quarantine in Microsoft 365 response:

domain.registration_metadata.registration_date.days_since:<30 AND
(
domain.classification.phishing:>=0.9 OR
domain.registration_metadata.registrar:*Global\ Domain\ Group* OR
domain.dns_mx:@*zoho*
)

Watchdog’s MX condition also required a domain with mail records but no website. No rule field expresses that, so this rule also matches Zoho-hosted domains that serve a website. Tighten it before enabling the response.

  • Confirm at least one email provider is connected and enabled.
  • For Microsoft 365, confirm ingestion is enabled and the selected source has its required permission: ThreatHunting.Read.All for Advanced Hunting or ExchangeMessageTrace.Read.All for Exchange Message Trace. Reauthorize older integrations to make Trace fallback available.
  • If Exchange Message Trace is selected, confirm the tenant has provisioned Microsoft’s required first-party service principal.
  • For Google Workspace, confirm Gmail audit logs are enabled and the source status is connected or no-data.
  • Confirm monitored domains have completed lookups. Email candidates are attached to existing monitored-domain workflows.
  • Allow for provider ingestion delay. The service polls a bounded recent window rather than reading mail synchronously.

Deactivate the integration in Have I Been Squatted to stop ingestion. To remove provider-side access completely, also revoke the application grant in Microsoft Entra Enterprise Applications or Google Workspace admin settings.