Detection

Environment scans

Baseline a tenant's email hygiene — SPF, DKIM, DMARC, blocklists, impersonation exposure and risky configuration.

7 min read
Radar sweep detecting mail infrastructure issues

What a scan covers

An environment scan is a point-in-time assessment of everything outside individual messages: DNS authentication records (SPF, DKIM, DMARC, MTA-STS, DNSSEC), blocklist and reputation checks on the sending infrastructure, lookalike-domain exposure, threat-feed matches, and tenant configuration such as forwarding rules and legacy authentication.

Each module returns findings with a severity and a remediation note; the results roll up into a posture score out of 100.

Run a scan

  1. 1Go to Env scans and choose the tenant.
  2. 2Click Run scan. Modules execute in parallel and the page updates as each finishes.
  3. 3Open any finding to see the evidence, why it matters, and the exact record or setting to change.

Scheduling scans

Scans can run automatically for every connected tenant on a schedule, so posture drift is caught without anyone remembering to click a button. Re-run a scan after remediation to prove the finding is closed — historical scores are kept so you can show improvement over time in the SOC report.