---
title: Emails
description: Watch how data actually moves through email - outbound sensitive content, impersonation via delegated sending, whole-conversation rollups, and thread evidence that survives deletion.
icon: Mail
---

# Emails

The Emails screen answers a question most organizations can't: **"Is data leaving through email - and would we even notice?"** Email is still the most common exit route for corporate data and the entry route for most compromises. 1Security turns your organization's mail flow into a security signal layer: direction, delegation, attachments, sensitivity, and thread evidence - without turning anyone's inbox into a surveillance feed. And because attacks unfold as exchanges, not single messages, the screen gives you two altitudes: individual **Emails** and whole-thread **Conversations**.

## What You Can Achieve

<Cards>
  <Card
    title="Catch data on its way out"
    description="Outbound mail to external recipients carrying sensitive detections, file attachments, or cloud links - the exfiltration shortlist, filterable in seconds instead of reconstructed after the fact."
  />
  <Card
    title="Spot impersonation and delegation abuse"
    description="Send-as, send-on-behalf, shared mailbox, and delegate sends are how business email compromise hides. Every message records how it was actually sent - not just who it claims to be from."
  />
  <Card
    title="Reconstruct threads - including what was deleted"
    description="Replies that reference a message absent from every scanned mailbox are evidence something was removed. 1Security preserves that trace instead of losing it with the deletion."
  />
  <Card
    title="Judge the exchange, not just the message"
    description="The Conversations view rolls every thread into one row - participants, files, accumulated sensitivity, and whether an external sender is getting internal replies. Attacks unfold as exchanges; now you can filter them that way."
  />
  <Card
    title="Get signals without reading everyone's mail"
    description="1Security stores communication metadata and security detections - directions, participants, flags, sensitive-info matches - not a browsable archive of message bodies."
  />
</Cards>

## The Signals That Matter

- **Direction** - inbound, outbound, or internal. Exfiltration analysis starts with outbound; phishing analysis with inbound.
- **Sending method** - direct, **send as**, **send on behalf**, **shared mailbox**, or **delegate access**. Delegated paths are legitimate features and favorite BEC disguises; here they're first-class filters.
- **Thread evidence** - every message is classified as a thread root, direct reply, or forward, and threads are linked across mailboxes. A reply whose parent is **missing** from all scanned mailboxes means the original was deleted or never passed through your tenant - either way, worth your attention.
- **Attachments three ways** - classic file attachments, **cloud attachments** (SharePoint/OneDrive links), and **unique uploads**: files sent by mail that exist nowhere in your Microsoft 365 estate. Data appearing from - or leaving to - places you don't control.
- **Verdicts and sensitivity** - spam, phishing, and malware flags, plus sensitivity labels, protection status, and 1Security's own sensitive-info detections with confidence levels.

## Two Views: Messages and Conversations

Tabs at the top of the screen switch between **Emails** - individual messages - and **Conversations** - whole threads rolled up into single rows - each with a live count. Same mail, two altitudes: the message view answers *"what exactly was sent?"*, the conversation view answers *"what is this exchange doing as a whole?"*

A conversation row aggregates its entire thread:

- **Started / Last activity** - when the thread began and when it last moved. Sort by last activity to see which exchanges are alive right now.
- **Thread length and participants** - every sender and recipient across the whole thread, not just the root message's addressees.
- **Files across the exchange** - attachments, cloud links, and uploads summed over every message in the thread.
- **Flags that stick** - a conversation is marked spam, phishing, or malware if **any** message in it was; sensitive-info detections accumulate across the thread.
- **Two-way exchange** - the thread contains both external and internal senders. An outside sender who *gets internal replies* is what a successful phish or social-engineering attempt looks like - a signal no single message can carry.
- **Sending method** - the riskiest method used anywhere in the thread: one delegated send marks the whole exchange.

Click a conversation to open its drawer: every message in the thread, participants, files, and a conversation graph that draws the reply chain - including inferred links where headers were stripped.

<Callout type="info">
  Conversation filters keep the familiar names but switch to thread semantics:
  **with sensitive info** matches threads where any message has detections,
  **type: forward** matches threads containing at least one forward, and
  **missing parent** flags threads whose original was deleted or never seen.
  You're filtering exchanges, not messages - per-message concepts like read
  status and thread position deliberately don't appear here.
</Callout>

## The Email List

Each row carries the investigative surface: subject, sender, recipient counts split internal vs. external, direction, sending method, thread role and length, autoreply likelihood, importance, attachment and upload indicators, security alerts, and timestamps. Filters cover every signal above, plus sender and recipient search and date ranges. Click a message to open its drawer with the full thread context; select messages and choose **Run actions** to trigger automation workflows.

## Investigative Patterns

<Callout type="info">
  **The exfiltration shortlist**: filter **outbound** + external recipients +
  **with sensitive info** + **unique uploads**. Sensitive content leaving the
  organization in files that never existed in SharePoint or OneDrive - the
  highest-signal mail view in the platform.
</Callout>

- **BEC sweep** - sending method **send as** or **delegate access** + outbound + external recipients: verify each delegated identity use is expected.
- **Cover-up traces** - **missing parent** + phishing or malware flags: threads where the incriminating original is already gone but the evidence chain survives.
- **Quiet forwarding** - type **forward** + external recipients + sensitive info: internal material being passed outside, one forward at a time.
- **Successful-phish check** - Conversations view: **two-way exchange** + inbound + phishing flag. Not the attempts that bounced off - the external senders who got answers.
- **Living sensitive threads** - Conversations view: **with sensitive info**, sorted by **last activity**. The exchanges still accumulating sensitive content today, not the ones that died last quarter.
