Skip to content

Email Security: one sensor per mailbox, the mailbox object, per-mailbox state examples - #463

Merged
maximelb merged 3 commits into
masterfrom
fbE/mailbox-sensors
Oct 2, 2026
Merged

maximelb merged 3 commits into
masterfrom
fbE/mailbox-sensors

Conversation

@maximelb

Copy link
Copy Markdown
Contributor

What

Email Security now puts each protected mailbox on its own sensor (platform email, hostname = the mailbox's primary address), instead of one sensor for the whole connection. This updates the docs to match:

  • automation.md: "The sensor" is rewritten as "The sensors": per-mailbox sensors, the connection-level sensor for events that are not about a mailbox (and why its online state is not an ingest health signal), what fixes a mailbox's sensor (provider id, not address), and the new event/mailbox/{id,address,upn} object that every mailbox-scoped event carries, including which mailbox EMAIL_USER_REPORT names.
  • automation.md: new "State per mailbox" section: per-sensor (non-global) suppression examples (one detection per recipient per sender domain per day, three malicious messages to one mailbox in an hour) and how to select one mailbox's sensor.
  • troubleshooting.md: the installation key FAQ no longer says one sensor per connection.

The per-user / global-suppression counter examples (counting across sensors, keyed by address or reporter) are covered by the separate "counting events per mailbox or per user" change; this PR does not duplicate them.

Notes for the reviewer

  • Do not merge before the feature ships to a release: it describes behavior that is not in a released build yet.
  • Cross-links to the global-suppression section are intentionally not added here so this builds independently of that change; add one when both are merged.

🤖 Generated with Claude Code

lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Oct 1, 2026
@limacharlie-refractionpoint

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation 36f44f2…17f9398 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb
maximelb merged commit ace2ea0 into master Oct 2, 2026
8 checks passed
@maximelb
maximelb deleted the fbE/mailbox-sensors branch October 2, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants