Skip to content

Email signals

Email signals describe persisted Email Intelligence events. Availability depends on the provider and event type. Email rules require Email Intelligence access and evaluate events linked to the monitored domain.

email.sender_from_domain:example.com AND
email.recipient_domains:@example.org
email.attachment_size_bytes:>1000000 AND
_exists_:email.attachment_sha256

Conditions within the Email namespace must match the same event. An attachment event and a URL event are separate records, even if the provider associates them with the same message.

domain.metadata.sources.provider describes how a domain result was discovered. email.provider describes an Email Intelligence event. They are different fields over different records.

16 signals

Email events 7
email.observed_on date
Timestamp when the email intelligence event was observed
email.provider string
Email intelligence provider
email.event_type string
Email intelligence event type
email.direction string
Email direction
email.sender_from_domain string
Normalized sender From domain
email.sender_mail_from_domain string
Normalized sender MailFrom domain
email.recipient_domains array<string>
Normalized recipient domains
URLs 2
email.url_domain string
Normalized observed URL domain
email.url_location string
Provider URL location label
Attachments 7
email.attachment_file_type string
Observed attachment file type
email.attachment_sha256 string
Observed attachment SHA-256 digest
email.attachment_sha1 string
Observed attachment SHA-1 digest
email.attachment_size_bytes number
Observed attachment size in bytes
email.threat_types array<string>
Provider attachment threat type labels
email.threat_names array<string>
Provider attachment threat names
email.detection_methods array<string>
Provider attachment detection methods