Skip to content

Signals and namespaces

A signal is a field that a query can inspect. Its namespace identifies the source of that field. Start with the source, then narrow the reference by signal group or field name.

domain.classification.phishing has two parts. domain selects the namespace; classification.phishing selects the field within that source.

domain.classification.phishing:>0.8

Existing Domain rules can keep unqualified names such as classification.phishing. In alert rules, an unqualified field resolves to Domain. Use explicit prefixes when writing rules that include Email or Canary. The compatibility-only created_on field is the exception: it must remain unqualified and records when the lookup result was created.

Namespace Data source Alert rules
domain Results from the current domain analysis Supported
email Email Intelligence events linked to the monitored domain Supported with Email Intelligence access
canary Site Canary events for the monitored domain Supported with Site Canaries access

In the visual builder, choose a namespace for each condition group. The field picker then shows that source’s fields. Email and Canary availability follows the organization’s feature access.

Matched results has separate Domain, Email, and Canary tabs. These previews search each source independently across organization data within the selected window. They do not simulate a complete rule run scoped to one monitored domain.

Conditions within one namespace apply to one record. Conditions across namespaces check for matching records independently within the monitored domain’s scope. They do not join an email, a Canary event, and a domain result into one correlated event.

See rules across namespaces for examples, time windows, and supported Boolean shapes.

A registered field may have no value on a particular record. Enrichment coverage, provider event type, scan results, and subscription access determine what data is present. Use _exists_: when presence itself matters.

Each namespace reference includes the public catalog’s exact field names, types, and descriptions. Search within a namespace or open one signal group at a time. See Upsilon query syntax for operators and type-specific behavior.