Emails
Watch how data actually moves through email - outbound sensitive content, impersonation via delegated sending, whole-conversation rollups, and thread evidence that survives deletion.
Emails
The Emails screen answers a question most organizations can't: "Is data leaving through email - and would we even notice?" Email is still the most common exit route for corporate data and the entry route for most compromises. 1Security turns your organization's mail flow into a security signal layer: direction, delegation, attachments, sensitivity, and thread evidence - without turning anyone's inbox into a surveillance feed. And because attacks unfold as exchanges, not single messages, the screen gives you two altitudes: individual Emails and whole-thread Conversations.
What You Can Achieve
Catch data on its way out
Outbound mail to external recipients carrying sensitive detections, file attachments, or cloud links - the exfiltration shortlist, filterable in seconds instead of reconstructed after the fact.
Spot impersonation and delegation abuse
Send-as, send-on-behalf, shared mailbox, and delegate sends are how business email compromise hides. Every message records how it was actually sent - not just who it claims to be from.
Reconstruct threads - including what was deleted
Replies that reference a message absent from every scanned mailbox are evidence something was removed. 1Security preserves that trace instead of losing it with the deletion.
Judge the exchange, not just the message
The Conversations view rolls every thread into one row - participants, files, accumulated sensitivity, and whether an external sender is getting internal replies. Attacks unfold as exchanges; now you can filter them that way.
Get signals without reading everyone's mail
1Security stores communication metadata and security detections - directions, participants, flags, sensitive-info matches - not a browsable archive of message bodies.
The Signals That Matter
- Direction - inbound, outbound, or internal. Exfiltration analysis starts with outbound; phishing analysis with inbound.
- Sending method - direct, send as, send on behalf, shared mailbox, or delegate access. Delegated paths are legitimate features and favorite BEC disguises; here they're first-class filters.
- Thread evidence - every message is classified as a thread root, direct reply, or forward, and threads are linked across mailboxes. A reply whose parent is missing from all scanned mailboxes means the original was deleted or never passed through your tenant - either way, worth your attention.
- Attachments three ways - classic file attachments, cloud attachments (SharePoint/OneDrive links), and unique uploads: files sent by mail that exist nowhere in your Microsoft 365 estate. Data appearing from - or leaving to - places you don't control.
- Verdicts and sensitivity - spam, phishing, and malware flags, plus sensitivity labels, protection status, and 1Security's own sensitive-info detections with confidence levels.
Two Views: Messages and Conversations
Tabs at the top of the screen switch between Emails - individual messages - and Conversations - whole threads rolled up into single rows - each with a live count. Same mail, two altitudes: the message view answers "what exactly was sent?", the conversation view answers "what is this exchange doing as a whole?"
A conversation row aggregates its entire thread:
- Started / Last activity - when the thread began and when it last moved. Sort by last activity to see which exchanges are alive right now.
- Thread length and participants - every sender and recipient across the whole thread, not just the root message's addressees.
- Files across the exchange - attachments, cloud links, and uploads summed over every message in the thread.
- Flags that stick - a conversation is marked spam, phishing, or malware if any message in it was; sensitive-info detections accumulate across the thread.
- Two-way exchange - the thread contains both external and internal senders. An outside sender who gets internal replies is what a successful phish or social-engineering attempt looks like - a signal no single message can carry.
- Sending method - the riskiest method used anywhere in the thread: one delegated send marks the whole exchange.
Click a conversation to open its drawer: every message in the thread, participants, files, and a conversation graph that draws the reply chain - including inferred links where headers were stripped.
Conversation filters keep the familiar names but switch to thread semantics: with sensitive info matches threads where any message has detections, type: forward matches threads containing at least one forward, and missing parent flags threads whose original was deleted or never seen. You're filtering exchanges, not messages - per-message concepts like read status and thread position deliberately don't appear here.
The Email List
Each row carries the investigative surface: subject, sender, recipient counts split internal vs. external, direction, sending method, thread role and length, autoreply likelihood, importance, attachment and upload indicators, security alerts, and timestamps. Filters cover every signal above, plus sender and recipient search and date ranges. Click a message to open its drawer with the full thread context; select messages and choose Run actions to trigger automation workflows.
Investigative Patterns
The exfiltration shortlist: filter outbound + external recipients + with sensitive info + unique uploads. Sensitive content leaving the organization in files that never existed in SharePoint or OneDrive - the highest-signal mail view in the platform.
- BEC sweep - sending method send as or delegate access + outbound + external recipients: verify each delegated identity use is expected.
- Cover-up traces - missing parent + phishing or malware flags: threads where the incriminating original is already gone but the evidence chain survives.
- Quiet forwarding - type forward + external recipients + sensitive info: internal material being passed outside, one forward at a time.
- Successful-phish check - Conversations view: two-way exchange + inbound + phishing flag. Not the attempts that bounced off - the external senders who got answers.
- Living sensitive threads - Conversations view: with sensitive info, sorted by last activity. The exchanges still accumulating sensitive content today, not the ones that died last quarter.
Activity Logs
A unified, three-year audit trail of who did what, when, from where, and on which device - across all of Microsoft 365, without premium licenses.
Sensitive Info
A live map of where regulated data actually lives - every sensitive information type traced to the files, emails, sites, groups, users, and apps that can reach it.