Threat Intelligence Dashboard
The Threat Intelligence Dashboard provides a comprehensive view of email-based threats targeting your organization. It aggregates data from DMARC failures, forensic reports, and reputation feeds to identify spoofing attempts and suspicious activity.
The Threat Intelligence Dashboard is available on Pro, Business, and Enterprise plans.
Key Metrics
- Total Threat Events — Count of authentication failures across all domains
- Unique Threat IPs — Number of distinct IP addresses involved in failures
- Rejection Rate — Percentage of threats blocked by your DMARC policy
- Trend — 30/60/90-day views of threat activity
Top Threat IPs
A ranked list of IP addresses with the most authentication failures. For each IP:
- Failure count and message volume
- Geographic location
- Reverse DNS and organization
- Reputation score from threat intelligence feeds
Geographic Distribution
A map showing where threat activity originates. Unusual geographic patterns may indicate targeted attacks or compromised infrastructure in specific regions.
Actions
- Investigate any IP to see detailed threat intelligence
- Block suspicious IPs via Allow/Block Rules
- Export threat data for security team review