Threat Hunt

Open Threat Hunt to search retained security metadata. Combine fields such as sender, recipient, subject, message ID, conversation ID, verdict, authentication results, domains, URLs, and date range. Results are designed for triage and correlation; they are not a mailbox archive.

Saved hunts are shared within the tenant when your role has the relevant manage permission. Rename or remove saved hunts from the result workspace. A search can return no matches even when the integration is healthy.

Message Trace

Message Trace searches messages evaluated by EmDash. Open a result to inspect sender and recipient metadata, subject, timestamps, verdict, model signals, authentication checks, indicators, attachment metadata, and related incidents.

Dynamic message detail URLs are tenant-scoped and return only records your session may investigate. Access to the full body, retained excerpts, screenshots, attachment rescans, URL sandbox runs, and AI analysis is separately permissioned.

Privacy boundary: Security Investigator access is intentionally metadata-first. Do not request or share a full message body when structured evidence is sufficient.

DMARC Operations

Open DMARC to review managed domains and aggregate reports. The workspace includes:

  • managed domains and DNS setup;
  • authentication trend and alignment rate;
  • sending sources and report detail;
  • policy and disposition findings;
  • recommendations and SPF flattening;
  • recent activity and pagination.

Enable a domain, publish the service-specific DNS records, and wait for receiver reports. A report period with no rows may simply have no usable aggregate data. Use the domain setup tab to confirm the published rua destination and policy.

  1. Start with a dashboard detection or queue item.
  2. Search the relevant sender, recipient, subject, or message ID in Message Trace.
  3. Open the message detail and review structured evidence before requesting privileged data.
  4. Correlate the result with Threat Hunt or DMARC source data.
  5. Create or update an incident from the relevant workflow when a response is needed.