Back to Top
Inc. 5000 analyzed. Most fail basic email security. Where do you stand? [2026 Report]
Authentication hero
Threat Intelligence

Threat detection and
reputation monitoring for your email domains

Monitors email attacks targeting your domains and sending infrastructure, with real-time impersonation detection and continuous visibility into domain reputation across every domain you operate.

What Threat Intelligence provides

Capabilities covering the security and reputation surface of your email domains, from blocklist monitoring and IP reputation to threat campaign detection and multi-workspace correlation.

Blocklist monitoring

Real-time monitoring across Spamhaus SBL, XBL, PBL, DBL, CSS, and BCL, plus SpamCop, Barracuda, Cloudmark, and others. Immediate alerting on new listings. Activity log for every listing and delisting event with timestamp and entity. Delisting guidance and status tracking through the remediation process.

Blocklist monitoring

IP & domain reputation

Per-IP drill-down: DNSBL status, threat score, target domains, hosting provider, country, attack volume. Per-domain: reputation score, email volume, pass rate, blocklist status, abuse type. Full activity log across both entity types. Spamhaus SIA integration for authoritative threat intelligence.

IP & domain reputation

Threat campaign detection

Unauthorized sender identification for IPs claiming to send from your domain. Correlation of sending data, geographic origin, timing, and targeting patterns to surface coordinated impersonation campaigns. Attribution to specific IPs with trajectory data such as escalating, plateauing, or winding down. Classification tags include: Abused, Botnet, Malware-dist, Phishing, Compromised.

Threat campaign detection

Multi-workspace correlation

Threat signals that span workspaces for MSPs and enterprises. Cross-workspace campaign detection identifies attacks targeting multiple client or business unit domains simultaneously. Portfolio-level overview of spoofing attempts, suspicious IPs, compromised IPs, and blocklisted domains. SIEM integration support.

Multi-workspace correlation

How the Email Trust Platform Address It

Observe → Assess → Control

Sender Insights runs the platform's three-layer operating model across the full email authentication surface.

OBSERVE

Ingest reputation and threat signals continuously

Blocklist status, IP and domain reputation, unauthorized sending activity, and threat intelligence feeds, including Spamhaus SIA, ingested continuously across all connected domains. Every listing, delisting, and score change captured in a searchable activity log.

ASSESS

Correlate signals and classify threats

Unauthorized sending data, geographic origin, timing patterns, and targeting behavior correlated to distinguish isolated events from coordinated campaigns. Threat classification tags applied automatically. Reputation trends analyzed over time to surface gradual degradation before it reaches delivery metrics.

CONTROL

Surface findings and route alerts

Findings surfaced with affected IPs, domains, and threat classification, ranked by severity. Alerts routed through configured notification channels for new listings, score changes, and campaign detection. SIEM integration for existing security tooling. Threat remediation actions typically applied in Domain Health.

Email Trust Platform

Interconnected across the Email Trust Platform

How Authentication connects to the rest of the platform.

Domain Health connects
CONNECTS TO

Authentication

Authentication enforcement status determines the domain's exposure to impersonation. Unauthorized senders identified in Authentication surface as threat signals here. Conversely, threat data such as active impersonation campaigns, and compromised IPs contextualize what Authentication shows about unauthenticated sending sources.

CONNECTS TO

DNS Manager

Threat remediation, DNS policy updates, DMARC enforcement changes, record modifications, are applied through DNS Manager's zone management tooling and tracked in its audit trail. DNSSEC and CAA certificate status monitored by DNS Manager are inputs into the security posture assessed by this module.

CONNECTS TO

Sender Insights

When sender reputation changes, Sender Insights shows what your own sending activity is doing while this module shows what external actors are doing using your domain. Together they separate your sending behavior from external impersonation as the source of any reputation movement, a separation that's not possible with either module alone.

Reputation monitoring and threat detection for your email domains