Skip to main content

Active Threat Detection Report

What is the Active Threat Detection Report

Updated this week

This report is available only in the Enforce product and requires Microsoft 365 or Google Connector set up.

The Active Threat Detection report is available in Enforce through Valimail Labs (opt-in via Personal Settings).

This report surfaces inbound messages that may pose a risk to your organization or to domains you own, helping you quickly identify potential threats reaching your inbox. For the initial release, the timeframe is a rolling 7 days.

Lookalike Domain Detection

One of the key signals in this report is lookalike sending domains. These domains are compared against the domains in your Domains list to identify subtle character differences that could indicate risk.

Lookalike domains may:

  • Closely resemble your legitimate domains while using alternative or visually similar characters
    Represent owned domains that haven’t yet been added to your Domains list

  • Indicate potentially malicious domains attempting to impersonate your brand

Labs Feature Notice

Active Threat Detection is currently a Valimail Labs feature. We are actively expanding the report with:

  • Additional risk signals

  • Expanding timeframe

  • New ways to investigate and take action on flagged messages

Because this is a Labs report, you can expect frequent updates and improvements over the coming weeks.

Did this answer your question?