Email signals
Email signals describe persisted Email Intelligence events. Availability depends on the provider and event type. Email rules require Email Intelligence access and evaluate events linked to the monitored domain.
Use Email fields
Section titled “Use Email fields”email.sender_from_domain:example.com ANDemail.recipient_domains:@example.orgemail.attachment_size_bytes:>1000000 AND_exists_:email.attachment_sha256Conditions within the Email namespace must match the same event. An attachment event and a URL event are separate records, even if the provider associates them with the same message.
domain.metadata.sources.provider describes how a domain result was discovered. email.provider describes an Email Intelligence event. They are different fields over different records.
Browse signals
Section titled “Browse signals”16 signals
No signals match these filters. Try a shorter term or choose all groups.
Email events 7
-
email.observed_ondate - Timestamp when the email intelligence event was observed
-
email.providerstring - Email intelligence provider
-
email.event_typestring - Email intelligence event type
-
email.directionstring - Email direction
-
email.sender_from_domainstring - Normalized sender From domain
-
email.sender_mail_from_domainstring - Normalized sender MailFrom domain
-
email.recipient_domainsarray<string> - Normalized recipient domains
URLs 2
-
email.url_domainstring - Normalized observed URL domain
-
email.url_locationstring - Provider URL location label
Attachments 7
-
email.attachment_file_typestring - Observed attachment file type
-
email.attachment_sha256string - Observed attachment SHA-256 digest
-
email.attachment_sha1string - Observed attachment SHA-1 digest
-
email.attachment_size_bytesnumber - Observed attachment size in bytes
-
email.threat_typesarray<string> - Provider attachment threat type labels
-
email.threat_namesarray<string> - Provider attachment threat names
-
email.detection_methodsarray<string> - Provider attachment detection methods