Message Headers

headers (collection)

#

Description

Message Data Model attribute: headers

Fields #

NameDescription
domainsAll domains found in the Received headers
hopsList of hops the message took from Sender to Recipient
in_reply_toIn-Reply-To header value which identifies its parent message if exists
ipsAll IP addresses found in the Received headers
mailerX-Mailer or User-Agent extracted from headers
message_idMessage-ID extracted from the header
referencesThe Message-IDs of the other messages within this chain
references[]The Message-IDs of the other messages within this chain
reply_toWhere replies should be delivered to

Example Message Record #

{
  "headers": {
    "date": "2021-02-03T12:09:40Z",
    "date_original_offset": "-5",
    "domains": [
      {
        "domain": "vps.server.com",
        "root_domain": "server.com",
        "sld": "server",
        "subdomain": "vps",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "tyrellcorp.io",
        "root_domain": "tyrellcorp.io",
        "sld": "tyrellcorp",
        "tld": "io",
        "valid": true
      },
      {
        "domain": "esa2.hc2528-13.iphmx.com",
        "root_domain": "iphmx.com",
        "sld": "iphmx",
        "subdomain": "esa2.hc2528-13",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "bn8nam11ft049.mail.protection.outlook.com",
        "root_domain": "outlook.com",
        "sld": "outlook",
        "subdomain": "bn8nam11ft049.mail.protection",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "bn8nam11ft049.eop-nam11.prod.protection.outlook.com",
        "root_domain": "outlook.com",
        "sld": "outlook",
        "subdomain": "bn8nam11ft049.eop-nam11.prod.protection",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "bn9pr03ca0612.outlook.office365.com",
        "root_domain": "office365.com",
        "sld": "office365",
        "subdomain": "bn9pr03ca0612.outlook",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "bn9pr03ca0612.namprd03.prod.outlook.com",
        "root_domain": "outlook.com",
        "sld": "outlook",
        "subdomain": "bn9pr03ca0612.namprd03.prod",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "byapr08mb5527.namprd08.prod.outlook.com",
        "root_domain": "outlook.com",
        "sld": "outlook",
        "subdomain": "byapr08mb5527.namprd08.prod",
        "tld": "com",
        "valid": true
      },
      {
        "domain": "mn2pr08mb6239.namprd08.prod.outlook.com",
        "root_domain": "outlook.com",
        "sld": "outlook",
        "subdomain": "mn2pr08mb6239.namprd08.prod",
        "tld": "com",
        "valid": true
      }
    ],
    "hops": [
      {
        "fields": [
          {
            "name": "Mime-Version",
            "position": 0,
            "value": "1.0"
          },
          {
            "name": "X-Microsoft-Antispam-Zap-Message-Info",
            "position": 1,
            "value": "rgqHu3DAQR/FhPR57j7aP9aOEcW2Q269mMMv61bqeZz57oV0wu+9jx4Tx0vnwSBMWYh7sJs3CTWMtlZfUrrOyiRlVpyzwJnqXMuE3SW29PvM7lMZAJsuh0jQPz0Y0lc8YW3yCIHyFwtgdwx0lFwppQrj+m9MMFhD7tt0im9FP1kAP6EEpyoPEBWEy1D7fMoF5GDjNsIyfoacYPy+lRcrFgsLq0aq6P94BTxGkyvQkmdKbt61oQ/gbcN+/xcyJrpjfbjs0wt949ZRMiDT6OkzTQpJQMzH3zDggeMHhoNjfbT7Hu2ljcBf18tO4++9e7CnfuvQ8Cqv4asBdDmSZ9o0xzq2ara+4Z57pHRcoIMZ1ldVxCXEXg2XAjXcRBa+h1/OkNDI9Xr7qi0vNbnJhuwXDkHe6BQCYaw5WYvzpHKm7nAZL/RNDDcZ2di0JdE0i0XIf4VJOh86SKhpgIeyL3ZgqneFEtbEuJ/O83nI+CYffsZqTbvEC+45iyutLfQhF5g462YO62KtBaGHwre8PLYnURJLAxumd9W5qHBIrdmqilwAQyKgN6/9XRjVK8kn2t1sTqudKY1XEEMAdRBLvC69PeL1pVwHqpfqsSo8Fyrak8wW0howAVfKAH9Idk0Y52qUMJ6CVkRQzAiemHYVpuF55cV9JwAfSJQ6ukI98vM/RRY=\r\n4RGh1MUSTt4/VZKbV+8mZrwld+j/yXqjsJGb7/4jebdYSxBMvnHMBHJtnlTbS1VxUSH0/HjHa31jRUrr+P+08JUPFGn9tnR8uWFfO0tGCbsAp5pRevMOghW5eND3wXBXRm68AHiILtXpkCthooN7Y/uh/qSxCjfFku8xBbeORYuDB0kUgC44JpwUth9+YoFEKpCToA79lFU4GEQjke12QD7CxCMy/kTbEvNbHgRM1Co3H2sBJw9TN8AOWabVAdTSdVNSt5w7txbd8atn27/xasxM3MHRWAukiWIzDHlv+PQGHxGsdsIWZj4Zmi0C5hdS1HAQElNQxUotTkiXc/ZNO2mZT0nndD/7SnZsaSVo2rKO4B5iHbOPhqTaWXOIjuBU6gZ/OYEdrpZOolrQweigsn2agKFpbIUc40udZR8kOLPFH4vbXZsq6rSq5+K8SqNaHCDrjrjH5TpdxPk0FigregCbwLm2pd1aueo9wGwjXlMTWr1SBTF/VWkbjKOvrr4woyUaPN70uHsuPDbkXrqSfFNHIyIG5AFHd/jSHR2EJuGMrHFb2nz9TWsGhY6v9xw+xWRT4gv4pKFWdOvsnUw/x6Nqqp1TOdNoUa4iW/9jA1Hmoz0TnYQC5ujFPdFve0WUWgjj1zP3RMl1p37K3y0bYYO+O2gGaBZatQ6T8zeJYP0="
          },
          {
            "name": "X-Microsoft-Antispam-Message-Info",
            "position": 2,
            "value": "K2qYuKhxn5vGRN4OLmOczcXpgGq1VtWpGA6uJG9J1k9hW0ceF01E08fkv57N2fwNiHtzjsuyk0mVMzClnNxrXg2t06ta9TXJ+LUb9wGmlKOYuw9TEi3ji/otLwNSVarW9mCGbYWAyY5HIvAcNNwVJblnubgbIoZwP6iXRwY4v2QBNHvKsj9k7FeGBqkgJFuU1qEqJbT0u4IkAuOyzUMBQ0nqUX5Y8rdfbcOY0q9lLSGfDJK376LRDoD5GdMLEe8y6nunLpPD8BX1LxYjBnpXkqCwph8X+0MQd9TcXLvL2X0jLJv2tMylM8ibSSboSYjR8irw04QX5IdCZg6OSH/Xavjv5vzzhMXeJ3e9U2yOmps0rs6NHW8RvUCDgb3pQeHH2JgIAQMXEqKE66TfSLkiT2ubUes7ykARPmKIcZzsYQVQKT2W+b1LBHljlBxxzEvl2vkQP/CuaIb+m1KOdPMgfilFIFDasGFY/c1WhT2lAyilqdebi4OGA/4A42efmxORRkBxPwGi822S+T1Ik6Yz6+Tf3zbS8nOZuMIO6ZXvA7PHIocg/0xiNhf6YjSQOH93TDqdFzH/VThnHy/X+zdjYjgWt+3gaq18slpVQ5V1LExZTlgCiSfD4UY8U5AAcBx82/9ryes1KeDrUZJ/E9VCUt/91bBBurgpSH2jjUE0ioejFz6Mn7wz8DkUM7YzL7ZIg0ew6uEpPAeQXYXvZ4O2eXSVjCy23C+UP5erTYZDJvVRKjZeMbLlNLSpTnroDrImtsRnJcslktPHZorSxRjFkbviyoPyu9T9yNE1WOGu+F/SQa84oOqG++rvwRgvFs1L24kgu/iEsSzl3Qfy7vweWODTnViWF9vHdh3zbb1/T5AnQ+RqFv1N57cDPby58UKjXkUVBH/fww9ljD9JZhk9ViQh0CS9aEkOSIluWDhbDjc8VmPs/Fio5wrwIn8I8oEu/r4PePCIg2TzumLmrkC6g/2Cfm6GQZbxGvnwxUw4jdwZLlzedoHtqrpxb8BsQUy7PYfN59sN8WyJ+SAHFe1qhFAlNGaSvglllpd0sCZHhDrKAe6L/AGd5y9s23fGN1A1H5f8KpqODd7P3m72ABi0CEoujASOT8LDzoCy0OF25vRJ4KpF4kSrbNGCADBOKojf52qGnFweDU+jewZDbhKT+DT/pk5sPtyWwjUbmJ/G+eT3FzBxxDC1OjeI+S5pbDkIdgCo37350M00OFgt5ffzPQ1dljKXwaRy2RkRNQvnFNOkrUaInmhewt3HG/D0b8JNQhpLN6vf/m88cVOzRpFra5so3llbhnqrPvbkZ+5tkeE95pxxIB5tjRCo4zloMNEt7FbbkC7yUZl54iz/ygva5QSHGRbMo8dLL8O12JBqLIG0Mq/YBJM47ePhitY+xxq81wb4B3lbaQHBq4vwbb6Ea+8Mirkqg1XPy0510b4HEsMeHoapRFO/SFilYwUKBqvrLGNi5AHvRuCpEbYwgJ5kgv+8Mkd77qq71l0mo1A5qvQMKNYpd2vNRUqnODIHgtMbxaDQSgE5xAuSQtuY0EA/Fgslequ34Nc7NJZerGIbQcu/Z74iMYSbYcB9nnSGGC4igT8fy3kej+ngo+lzx3bRvuHLzoJFrAeHfgJEwrTO8sPypVH2yAPCzZMl8vE5QmSQqYVNkA7q/x45dNoKmoqLkFArCEDtD0A0CgvBgXiBrihWy8Pkwm8QGA8s155qXt7RHhSQhNNjjHRJ9IKFNIUxuufX5wwJSoMcFBkTD8Q6GGrVHWDG0EmXQibxfyaNwPTYp414zJxEjabuP01Y2ePSfTqpBNezunyPy0cGeNhiH9W4RwBEr1kgmgVEEx5ItiQCdYv6zQSq8C0ENovTJQXEuUG+PR/X9mmkXnF2B5njy/rWE9BoIX1Zdqc1xTeiwE3nSm+EtWt5hbfW8eeBXR7REw=="
          },
          {
            "name": "X-Microsoft-Antispam-Mailbox-Delivery",
            "position": 3,
            "value": "ucf:0;jmr:0;auth:0;dest:I;ENG:(750128)(520011016)(944506458)(944626604);"
          },
          {
            "name": "X-Ms-Exchange-Processed-By-Bccfoldering",
            "position": 4,
            "value": "15.20.3805.025"
          },
          {
            "name": "X-Ms-Exchange-Transport-Endtoendlatency",
            "position": 5,
            "value": "00:00:04.5082358"
          },
          {
            "name": "X-Ms-Exchange-Transport-Crosstenantheadersstamped",
            "position": 6,
            "value": "BYAPR08MB5527"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Fromentityheader",
            "position": 7,
            "value": "Internet"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Authas",
            "position": 8,
            "value": "Anonymous"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Authsource",
            "position": 9,
            "value": "BN8NAM11FT049.eop-nam11.prod.protection.outlook.com"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Id",
            "position": 10,
            "value": "3063c015-52d3-4e0f-8074-4426a1cfd3cb"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Network-Message-Id",
            "position": 11,
            "value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
          },
          {
            "name": "X-Ms-Exchange-Crosstenant-Originalarrivaltime",
            "position": 12,
            "value": "03 Feb 2021 12:09:43.5789 (UTC)"
          },
          {
            "name": "X-Forefront-Antispam-Report",
            "position": 13,
            "value": "CIP:216.71.148.252;CTRY:US;LANG:en;SCL:-1;SRV:;IPV:CAL;SFV:SKN;H:esa2.hc2528-13.iphmx.com;PTR:esa2.hc2528-13.iphmx.com;CAT:NONE;SFS:;DIR:INB;"
          },
          {
            "name": "X-Microsoft-Antispam",
            "position": 14,
            "value": "BCL:0;"
          },
          {
            "name": "X-Ms-Exchange-Organization-Scl",
            "position": 15,
            "value": "-1"
          },
          {
            "name": "X-Ms-Oob-Tlc-Oobclassifiers",
            "position": 16,
            "value": "OLM:1850;"
          },
          {
            "name": "X-Ms-Traffictypediagnostic",
            "position": 17,
            "value": "BYAPR08MB5527:"
          },
          {
            "name": "X-Ms-Office365-Filtering-Correlation-Id",
            "position": 18,
            "value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
          },
          {
            "name": "X-Ms-Exchange-Organization-Authas",
            "position": 19,
            "value": "Anonymous"
          },
          {
            "name": "X-Ms-Exchange-Organization-Authsource",
            "position": 20,
            "value": "BN8NAM11FT049.eop-nam11.prod.protection.outlook.com"
          },
          {
            "name": "X-Ms-Publictraffictype",
            "position": 21,
            "value": "Email"
          },
          {
            "name": "X-Ms-Exchange-Organization-Messagedirectionality",
            "position": 22,
            "value": "Incoming"
          },
          {
            "name": "X-Eoptenantattributedmessage",
            "position": 23,
            "value": "3063c015-52d3-4e0f-8074-4426a1cfd3cb:0"
          },
          {
            "name": "X-Eopattributedmessage",
            "position": 24,
            "value": "0"
          },
          {
            "name": "X-Ms-Exchange-Organization-Network-Message-Id",
            "position": 25,
            "value": "8d992cc4-63d2-4438-a152-08d8c83c9792"
          },
          {
            "name": "X-Ms-Exchange-Organization-Expirationintervalreason",
            "position": 26,
            "value": "OriginalSubmit"
          },
          {
            "name": "X-Ms-Exchange-Organization-Expirationinterval",
            "position": 27,
            "value": "1:00:00:00.0000000"
          },
          {
            "name": "X-Ms-Exchange-Organization-Expirationstarttimereason",
            "position": 28,
            "value": "OriginalSubmit"
          },
          {
            "name": "X-Ms-Exchange-Organization-Expirationstarttime",
            "position": 29,
            "value": "03 Feb 2021 12:09:43.9487 (UTC)"
          },
          {
            "name": "Return-Path",
            "position": 30,
            "value": "root@vps.server.com"
          },
          {
            "name": "Content-Transfer-Encoding",
            "position": 31,
            "value": "base64"
          },
          {
            "name": "Content-Type",
            "position": 32,
            "value": "text/html; charset=UTF-8"
          },
          {
            "name": "From",
            "position": 33,
            "value": "\"HR tyrellcorp <noreply@tyrellcorp.io>\" <rachael@tyrellcorp.io>"
          },
          {
            "name": "Subject",
            "position": 34,
            "value": "A file was shared with you tyrellcorp-Covid-19 Vaccination And Testing Report.pdf."
          },
          {
            "name": "Replyto",
            "position": 35,
            "value": ""
          },
          {
            "name": "To",
            "position": 36,
            "value": "rachael@tyrellcorp.io"
          },
          {
            "name": "Date",
            "position": 37,
            "value": "Wed, 03 Feb 2021 07:09:40 -0500"
          },
          {
            "name": "Message-Id",
            "position": 38,
            "value": "<202102031209.113C9eDc031722@vps.server.com>"
          }
        ],
        "index": 0
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 39,
            "value": "(from root@localhost) by vps.server.com (8.14.7/8.14.7/Submit) id 113C9eDc031722; Wed, 3 Feb 2021 07:09:40 -0500"
          }
        ],
        "index": 1
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 40,
            "value": "from vps.server.com (localhost [127.0.0.1]) by vps.server.com (8.14.7/8.14.7) with ESMTP id 113C9e2c031727 for <rachael@tyrellcorp.io>; Wed, 3 Feb 2021 07:09:40 -0500"
          }
        ],
        "index": 2
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 41,
            "value": "from unknown (HELO vps.server.com) ([185.243.112.105]) by esa2.hc2528-13.iphmx.com with ESMTP/TLS/ECDHE-RSA-AES128-GCM-SHA256; 03 Feb 2021 07:09:42 -0500"
          },
          {
            "name": "X-Amp-File-Uploaded",
            "position": 42,
            "value": "False"
          },
          {
            "name": "X-Amp-Result",
            "position": 43,
            "value": "SKIPPED(no attachment in message)"
          },
          {
            "name": "X-Ironport-Av",
            "position": 44,
            "value": "E=Sophos;i=\"5.79,398,1602561600\"; d=\"scan'208,217\";a=\"1650488\""
          },
          {
            "name": "X-Ironport-Anti-Spam-Filtered",
            "position": 45,
            "value": "true"
          },
          {
            "name": "Ironport-Phdr",
            "position": 46,
            "value": "9a23:jU3PyR9CP0SRz/9uRHKM819IXTAuvvDOBiVQ1KB+0+0TIJqq85mqBkHD//Il1AaPAdyKra4ewLGM++C4ACpcuMnH6ChDOLV3FDY9wf0MmAIhBMPXQWbaF9XNKxIAIcJZSVV+9Gu6O0UGUOz3ZlnVv2HgpWVKQka3OgV6PPn6FZDPhMqrye+y54fTYwJVjzahfL9+Nhq7oRjVu8UMjoZuNKk9xxXXrnBVf+ha2X5kKUickhrh5Mq85oJv/zhVt/k868NOTKL2crgiQ7dFFjomKWc15MPqtRnHUwSC42YXX3sVnBRVHQXL9Qn2UZjtvCT0sOp9wzSaMtbtTb8oQzSi7rxkRwHuhSwaKjM26mDXish3jKJGvBKsogF0zoDIbI2JMvd1Y6TScM8USGZdQ8pdTjBNDp6hZIcLEuYMPeNUoo/6qFYTtxSxGAmiBPnoyj9Nn3P40qI33/k8HQ3f3AEsA88FvHDVodnpMasfV+e6wbfPzTrZdPNWxS3y6IzRfh4vrvyAQax8fdPNxUUxDg/LjFKQqZf5PziI0ugAvXSX4/ZlWe+plmUpqRx+oiK3y8gjhIfHmJ8bxFDY+it224s1Jca3RFJnbdK4DJddtSeXPJZ2TMM4RGFovT43xrMEt5CnYSMF1oonxxnaa/OdaYiI4QzsVPqKITxlg39lfrW/hwys/ki4zu39VtK530hUripCl9nDrGoN1x/N5cibUftx5Fuu2TGK1w3K5O1PPEc5mrTBJJ4737E9jYQcsVrEHi/zgkr2lqyWeVs4+uiz8ejofrLmppqFOoJylwrxPbgglNalDuQkLggBQXKb+eKk2bDg/UD0XbRHg+M2n6XErJzXO8AWq7KlDwJbzIsu9RSyAjm63dkagHUKMk5IdRCIgoXtNFzCPu70Aeuhj1ixnjlmwe3NMLPmApXINHfDkbHhcK5g5E5dxwozzMxf6IhQCrEGPP38RFX+tNrDDh8hKQO73/joCM5n2owCXmKPB6mUO77Rv1+Q/u8jPuqBaY8PtDrjJPUo6eTigWIklVMDZ6WlwIcbZXC+E/97OUuWe2Dsjc0EEWoSvgoxUujqiFqaXD5Nf3ayRLgw5iolB4K8E4fMWJqtjKad0ye8G51afmFGClaSHnf0b4iIRvQBZSKILsN/nTEJW6KtR5I82R2wrgP21qZrI+rM9i0dr53j1dx15+PJlRE18Dx5F96d02aKT2FohW4IWSc23LtlrUxm1FiDy7Z4jOJCFdBJ+/xJVQI6OYbGz+NmE9DyRh7BftCRRVm4WNqmGyw+Q8kvzN8QZEZ9Hs+tjgrA3yW0H78VjKaHC4Az8qLZjDDNIJNwwmzK/KQ/iFwvWMhCKXbgjal6pCbJAIuc2WWj36u0cqEVxi3A6HzLmWyJpkxAVB9YXLvCWHkFZUbKtpLy4UaUBff6BL09PiNM18mHI7FJZ8Hyy15BQaGwa5zlf2utljLpVl6zzbSWYd+xJDgQ"
          },
          {
            "name": "X-Ipas-Result",
            "position": 47,
            "value": "A0lFXQDMkRpgl2lw87liGwEDAwEFARYBAwMBQgeBSAIBDA4IAX0BGgKBYXoSFxqEQIgmXoY7AYIXgxgBkT4BhQ1mE4EsPQoBAQEBAQEBAQEJJwgEAQECgy6BGhkHgWABJTwCDQIDAQEBAwQBAQEBAQEEAQEBAgEBBgECAQEBARABAQEBAQEBAXNtWYM+CgQxDT+CBQEEAQEBAQMDAwEBDAEOYk06AQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBBQInGzkcSxERUxoNAiYCBBQzJyKCbxUBgwoBCj6iJQGBKD4CIwFAAQyBCIkRAQEBdIEyGgKEJAGGGgWBCRMVAgEBhnodhiYmGz4BgUGBR4QKgRVfAwEGgRk5UoJMF4InCBoEgVWBHGSBBDJ3IgMUjBsBg3qMCnqJOpItBwOCeoEZJAGHeJJugy+BM4kThVQDiF+CAIFgglFEhj6XcoErlnKCBAqBWhUjOBWDJAlEAQIBAQENAQICAwECAQFfB417gzqKdiMDMAIBAQERHgMCBgoBAQMJjBUBAQ"
          },
          {
            "name": "X-Ironport-Mailflowpolicy",
            "position": 48,
            "value": "$ACCEPTED"
          },
          {
            "name": "X-Ironport-Sendergroup",
            "position": 49,
            "value": "UNKNOWNLIST"
          },
          {
            "name": "X-Ironport-Listener",
            "position": 50,
            "value": "BidirectionalMail"
          },
          {
            "name": "X-Ironport-Reputation",
            "position": 51,
            "value": "5.1"
          },
          {
            "name": "X-Ironport-Mid",
            "position": 52,
            "value": "1650488"
          },
          {
            "name": "X-Ironport-Remoteip",
            "position": 53,
            "value": "185.243.112.105"
          },
          {
            "name": "Ironport-Sdr",
            "position": 54,
            "value": "cTti+076Q288FeDFpFsjC2m03kAZNiHNTZouC3doe3gr1hSLmWJJmSmAuO9FXL6rfcfsGqD3MS +IoDTZtzNOYqw08W3kHp5diTvmQ50ZX7VDHDMrVd1L9pimUfppiy1ZZOBzDEIRpI2p8JeXSf1Q p+rhTH7W4jonDFHdvVCoGNJDOEto26ccJKowjycrrxYlnPO4vjpUxGVujRNFmK36VJMCO8UbSf 3D1wJueE9dS6gXQ02YdaGYgBozgcG6B3YW43tRJQv+KWosz4nIclTtMpPQ4rvZLP7QlNeq/tF4 YNQwsYR33uHVxSiFiEa52et5"
          }
        ],
        "index": 3
      },
      {
        "authentication_results": {
          "compauth": {
            "reason": "905",
            "verdict": "none"
          },
          "dkim_details": [
            {
              "domain": "none",
              "type": "dkim"
            }
          ],
          "dmarc": "none",
          "dmarc_details": {
            "action": "none",
            "from": {
              "domain": "tyrellcorp.io",
              "root_domain": "tyrellcorp.io",
              "sld": "tyrellcorp",
              "tld": "io",
              "valid": true
            },
            "verdict": "none",
            "version": ""
          },
          "server": {
            "domain": "tyrellcorp.io",
            "root_domain": "tyrellcorp.io",
            "sld": "tyrellcorp",
            "tld": "io",
            "valid": true
          },
          "spf": "none",
          "spf_details": {
            "client_ip": {
              "ip": "216.71.148.252"
            },
            "description": "sender IP is 216.71.148.252",
            "designator": "vps.server.com",
            "verdict": "none"
          },
          "type": "standard"
        },
        "fields": [
          {
            "name": "Received",
            "position": 55,
            "value": "from esa2.hc2528-13.iphmx.com (216.71.148.252) by BN8NAM11FT049.mail.protection.outlook.com (10.13.177.157) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3784.12 via Frontend Transport; Wed, 3 Feb 2021 12:09:43 +0000"
          },
          {
            "name": "Received-Spf",
            "position": 56,
            "value": "None (protection.outlook.com: vps.server.com does not designate permitted sender hosts)"
          },
          {
            "name": "Authentication-Results",
            "position": 57,
            "value": "spf=none (sender IP is 216.71.148.252) smtp.mailfrom=vps.server.com; tyrellcorp.io; dkim=none (message not signed) header.d=none;tyrellcorp.io; dmarc=none action=none header.from=tyrellcorp.io;compauth=none reason=905"
          }
        ],
        "index": 4,
        "received_spf": {
          "client_ip": {
            "ip": ""
          },
          "description": "protection.outlook.com: vps.server.com does not designate permitted sender hosts",
          "designator": "vps.server.com",
          "server": {
            "domain": "protection.outlook.com",
            "root_domain": "outlook.com",
            "sld": "outlook",
            "subdomain": "protection",
            "tld": "com",
            "valid": true
          },
          "verdict": "None"
        }
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 58,
            "value": "from BN8NAM11FT049.eop-nam11.prod.protection.outlook.com (2603:10b6:408:106:cafe::de) by BN9PR03CA0612.outlook.office365.com (2603:10b6:408:106::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3805.17 via Frontend Transport; Wed, 3 Feb 2021 12:09:44 +0000"
          }
        ],
        "index": 5
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 59,
            "value": "from BN9PR03CA0612.namprd03.prod.outlook.com (2603:10b6:408:106::17) by BYAPR08MB5527.namprd08.prod.outlook.com (2603:10b6:a03:c4::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3805.24; Wed, 3 Feb 2021 12:09:45 +0000"
          }
        ],
        "index": 6
      },
      {
        "fields": [
          {
            "name": "Received",
            "position": 60,
            "value": "from BYAPR08MB5527.namprd08.prod.outlook.com (2603:10b6:a03:c4::12) by MN2PR08MB6239.namprd08.prod.outlook.com with HTTPS; Wed, 3 Feb 2021 12:09:48 +0000"
          }
        ],
        "index": 7
      }
    ],
    "ips": [
      {
        "ip": "127.0.0.1"
      },
      {
        "ip": "185.243.112.105"
      },
      {
        "ip": "216.71.148.252"
      },
      {
        "ip": "10.13.177.157"
      }
    ],
    "message_id": "<202102031209.113C9eDc031722@vps.server.com>",
    "return_path": {
      "domain": {
        "domain": "vps.server.com",
        "root_domain": "server.com",
        "sld": "server",
        "subdomain": "vps",
        "tld": "com",
        "valid": true
      },
      "email": "root@vps.server.com",
      "local_part": "root"
    }
  }
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam58 rulesmql
headers.referenceslength_compare046 rulesmql
headers.in_reply_tois_null45 rulesmql
body.linkslength_compare036 rulesmql
body.linkslength_compare1019 rulesmql
headers.reply_tolength_compare032 rulesmql
recipients.tolength_compare024 rulesmql
recipients.tolength_compare124 rulesmql
headers.auth_summary.dmarc.passeqtrue18 rulesmql
headers.auth_summary.spf.passeqtrue18 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam14 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().prevalence in (new, outlier)9 rulesmql
recipients.cclength_compare014 rulesmql
body.previous_threadslength_compare012 rulesmql
recipients.bcclength_compare012 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.auth_summary

#

Description

Message Data Model attribute: headers.auth_summary

Fields #

NameDescription
dmarc.details.from.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
dmarc.details.from.root_domainThe root domain, including the TLD
dmarc.passWhether the DMARC check passed
spf.details.designatorEmail or domain of the designating body
spf.passWhether the SPF check passed

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
type.inboundeqtrue466 rulesmql
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam91 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)24 rulesmql
attachmentslength_compare043 rulesmql
body.linkslength_compare041 rulesmql
body.linkslength_compare1026 rulesmql
headers.auth_summary.dmarc.passeqtrue36 rulesmql
headers.auth_summary.spf.passeqtrue32 rulesmql
headers.in_reply_tois_null29 rulesmql
headers.referenceslength_compare029 rulesmql
recipients.tolength_compare023 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam21 rulesmql
headers.reply_tolength_compare016 rulesmql
recipients.cclength_compare014 rulesmql
body.current_thread.textcontainsinvoice13 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.domains (collection)

#

Description

Message Data Model attribute: headers.domains

Fields #

NameDescription
domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
root_domainThe root domain, including the TLD
tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'

Example Message Record #

{
  "headers.domains": [
    {
      "domain": "vps.server.com",
      "root_domain": "server.com",
      "sld": "server",
      "subdomain": "vps",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "tyrellcorp.io",
      "root_domain": "tyrellcorp.io",
      "sld": "tyrellcorp",
      "tld": "io",
      "valid": true
    },
    {
      "domain": "esa2.hc2528-13.iphmx.com",
      "root_domain": "iphmx.com",
      "sld": "iphmx",
      "subdomain": "esa2.hc2528-13",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "bn8nam11ft049.mail.protection.outlook.com",
      "root_domain": "outlook.com",
      "sld": "outlook",
      "subdomain": "bn8nam11ft049.mail.protection",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "bn8nam11ft049.eop-nam11.prod.protection.outlook.com",
      "root_domain": "outlook.com",
      "sld": "outlook",
      "subdomain": "bn8nam11ft049.eop-nam11.prod.protection",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "bn9pr03ca0612.outlook.office365.com",
      "root_domain": "office365.com",
      "sld": "office365",
      "subdomain": "bn9pr03ca0612.outlook",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "bn9pr03ca0612.namprd03.prod.outlook.com",
      "root_domain": "outlook.com",
      "sld": "outlook",
      "subdomain": "bn9pr03ca0612.namprd03.prod",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "byapr08mb5527.namprd08.prod.outlook.com",
      "root_domain": "outlook.com",
      "sld": "outlook",
      "subdomain": "byapr08mb5527.namprd08.prod",
      "tld": "com",
      "valid": true
    },
    {
      "domain": "mn2pr08mb6239.namprd08.prod.outlook.com",
      "root_domain": "outlook.com",
      "sld": "outlook",
      "subdomain": "mn2pr08mb6239.namprd08.prod",
      "tld": "com",
      "valid": true
    }
  ]
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
beta.ocr(file.message_screenshot()).textcontainsreview2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsview2 rulesmql
body.current_thread.textcontainsblocked2 rulesmql
body.current_thread.textcontainsnotification2 rulesmql
body.current_thread.textcontainsprevented2 rulesmql
body.current_thread.textcontainsreview2 rulesmql
body.current_thread.textcontainsserver error2 rulesmql
body.current_thread.textcontainsunsubscribe2 rulesmql
body.current_thread.textcontains2884 sand hill road1 rulemql
body.current_thread.textlength_compare2502 rulesmql
body.current_thread.textlength_compare7002 rulesmql
body.current_thread.textregex_match\+?([ilo0-9]{1,2})?\s?\(?\d{3}\)?[\s\.\-⋅]{0,5}[ilo0-9]{3}[\s\.\-⋅]{0,5}[ilo0-9]{4}2 rulesmql
body.current_thread.textregex_match\+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4}2 rulesmql
filter(body.links, .href_url.scheme != 'mailto')length_compare02 rulesmql
sender.display_nameregex_match[a-z0-9]+@[a-z]+2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.hops (collection)

#

Description

Message Data Model attribute: headers.hops

Fields #

NameDescription
authentication_results.compauth.verdictVerdict of the compauth
authentication_results.dkimVerdict of the Domain Keys Identified Mail check
authentication_results.dkim_detailsList of details of the Domain Keys Identified Mail checks
authentication_results.dkim_details[].domainDomain identified in the DKIM signature if any. This is the domain that's queried for the public key.
authentication_results.dmarcVerdict of the Domain-based Message Authentication, Reporting & Conformance check
authentication_results.dmarc_details.from.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
authentication_results.spfVerdict of the Sender Policy Framework
authentication_results.spf_details.designatorEmail or domain of the designating body
fieldsList of all raw header fields contained within this hop
fields[].nameThe name of the field
fields[].valueThe value contained within the field
indexIndex indicates the order in which a hop occurred from sender to recipient
received.server.rawThe raw string of 'by' section
received.source.rawThe raw string of 'from' section
received_spf.designatorEmail or domain of the designating body
signature.headersHeader fields signed by the algorithm

Example Message Record #

{
  "headers.hops": [
    {
      "fields": [
        {
          "name": "Content-Type",
          "position": 0,
          "value": "multipart/alternative; boundary=\"00000000000041de5d05956fc8ff\""
        },
        {
          "name": "To",
          "position": 1,
          "value": "ian@sublimesecurity.com"
        },
        {
          "name": "Subject",
          "position": 2,
          "value": "Urgent: Need W2s"
        },
        {
          "name": "Message-Id",
          "position": 3,
          "value": "<CAO_do4n4jwcfabQcEScYd9oSjDytgm_PveKKiF_gtBEYL8a0XQ@mail.gmail.com>"
        },
        {
          "name": "Date",
          "position": 4,
          "value": "Mon, 21 Oct 2019 14:23:24 -0400"
        },
        {
          "name": "From",
          "position": 5,
          "value": "Joshua Kamdjou <joshkamdjou90@gmail.com>"
        },
        {
          "name": "Mime-Version",
          "position": 6,
          "value": "1.0"
        }
      ],
      "index": 0
    },
    {
      "authentication_results": {
        "dkim": "pass",
        "dkim_details": [
          {
            "selector": "20161025",
            "signature": "ehHYOeNl",
            "type": "dkim"
          }
        ],
        "dmarc": "pass",
        "dmarc_details": {
          "action": "",
          "disposition": "NONE",
          "from": {
            "domain": "gmail.com",
            "root_domain": "gmail.com",
            "sld": "gmail",
            "tld": "com",
            "valid": true
          },
          "policy": "NONE",
          "sub_policy": "QUARANTINE",
          "verdict": "pass",
          "version": ""
        },
        "spf": "pass",
        "spf_details": {
          "client_ip": {
            "ip": "209.85.220.41"
          },
          "description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
          "designator": "joshkamdjou90@gmail.com",
          "server": {
            "domain": "google.com",
            "root_domain": "google.com",
            "sld": "google",
            "tld": "com",
            "valid": true
          },
          "verdict": "pass"
        },
        "type": "standard"
      },
      "fields": [
        {
          "name": "X-Received",
          "position": 7,
          "value": "by 2002:a92:98d8:: with SMTP id a85mr26122504ill.98.1571682217220; Mon, 21 Oct 2019 11:23:37 -0700 (PDT)"
        },
        {
          "name": "X-Google-Smtp-Source",
          "position": 8,
          "value": "APXvYqxfE+fdj3jGAojIsortyqTNR1ENm62PygXYKTqDYckHdh7KidULa/8SDeiB1Ps2nUSdRWovZ3PmLrHWEYTKcUM="
        },
        {
          "name": "X-Gm-Message-State",
          "position": 9,
          "value": "APjAAAVb/mSXq4NJu3c7kNHqknwEGp+eM42+kc6mXX24l99qU1v5jye3 pkOTMEXLRcUUpLcn4Iyu8dy7L0IuAAK7NxEuPsemag=="
        },
        {
          "name": "X-Google-Dkim-Signature",
          "position": 10,
          "value": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=P8xfZoR5KiUmlqs6fZgxEJ8iA4FJ4gFOORhUiv6a7U4QCGDQOz1uGO0eaMJVorUFxG sWhSjONT6TuAHnAsTlbau8f6WozxX6XhUWTMzXFQ110YV3XI5ZSoa4QhrIoOkdkbdEFl Y6+QKc+HZlzvRhaPS8VOF0cqr2Nn6bjtb03AxjIHSCJUMd0TAs6ejofnaDtiIF/vQuVP AdXFUIYlRMNMKRzWv3PNvdUUFmcevbbJ9QGEKadAGTHD+tA2ZXy+1tu822Z0Rd0Z0stH RHb5lvJhtdp3NiphSFrOkZZXg2ffouEJ/nvYcGJll8gxT4LVWPbkQwH6zHsuMeG9CS9O l1dQ=="
        },
        {
          "name": "Dkim-Signature",
          "position": 11,
          "value": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=ehHYOeNliqIXd1VH8iKAMXAamG14fB/cNjH+zRkLMvXIiKrk0cmaZcXHa6L8JmJMlB tMJ/QEm9bOCfaHo1AWXJHtitwTrW0kjI4yAKFnlak82PJ20fDkcRuRmtO18GRINrg3/l 11WGWONbqw/Hh6+Az9slE5dR9sXQDhjK3ibNgev+A7KdUrj/gSY3kLWXj20VqxchN7ze DtHYxI5YtQnyeXVIHtiZ1E2DtpfkWgl6SWY9PIoBkmsd64aBrvUbMh8dC14u/qfn4N+Q wMGR1BQW7P8GP0jazwXXTfBeA8NwlORTCLMrcxNyzaQeUC3g4xxDF4krj2xsewk8j9Tr 1N9g=="
        },
        {
          "name": "Authentication-Results",
          "position": 12,
          "value": "mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ehHYOeNl; spf=pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=joshkamdjou90@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com"
        },
        {
          "name": "Received-Spf",
          "position": 13,
          "value": "pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;"
        }
      ],
      "index": 1,
      "received": "by 2002:a92:98d8:: with SMTP id a85mr26122504ill.98.1571682217220; Mon, 21 Oct 2019 11:23:37 -0700 (PDT)",
      "received_spf": {
        "client_ip": {
          "ip": "209.85.220.41"
        },
        "description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
        "designator": "domain of joshkamdjou90@gmail.com",
        "server": {
          "domain": "google.com",
          "root_domain": "google.com",
          "sld": "google",
          "tld": "com",
          "valid": true
        },
        "verdict": "pass"
      },
      "signature": {
        "algorithm": "rsa-sha256",
        "body_hash": "A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=",
        "domain": "gmail.com",
        "headers": "mime-version:from:date:message-id:subject:to",
        "selector": "20161025",
        "signature": "ehHYOeNliqIXd1VH8iKAMXAamG14fB/cNjH+zRkLMvXIiKrk0cmaZcXHa6L8JmJMlB tMJ/QEm9bOCfaHo1AWXJHtitwTrW0kjI4yAKFnlak82PJ20fDkcRuRmtO18GRINrg3/l 11WGWONbqw/Hh6+Az9slE5dR9sXQDhjK3ibNgev+A7KdUrj/gSY3kLWXj20VqxchN7ze DtHYxI5YtQnyeXVIHtiZ1E2DtpfkWgl6SWY9PIoBkmsd64aBrvUbMh8dC14u/qfn4N+Q wMGR1BQW7P8GP0jazwXXTfBeA8NwlORTCLMrcxNyzaQeUC3g4xxDF4krj2xsewk8j9Tr 1N9g==",
        "type": "dkim",
        "version": "1"
      }
    },
    {
      "authentication_results": {
        "dkim": "pass",
        "dkim_details": [
          {
            "selector": "20161025",
            "signature": "ehHYOeNl",
            "type": "dkim"
          }
        ],
        "dmarc": "pass",
        "dmarc_details": {
          "action": "",
          "disposition": "NONE",
          "from": {
            "domain": "gmail.com",
            "root_domain": "gmail.com",
            "sld": "gmail",
            "tld": "com",
            "valid": true
          },
          "policy": "NONE",
          "sub_policy": "QUARANTINE",
          "verdict": "pass",
          "version": ""
        },
        "instance": "1",
        "spf": "pass",
        "spf_details": {
          "client_ip": {
            "ip": "209.85.220.41"
          },
          "description": "google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender",
          "designator": "joshkamdjou90@gmail.com",
          "server": {
            "domain": "google.com",
            "root_domain": "google.com",
            "sld": "google",
            "tld": "com",
            "valid": true
          },
          "verdict": "pass"
        },
        "type": "arc"
      },
      "fields": [
        {
          "name": "Received",
          "position": 14,
          "value": "from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id h17sor9568062ilr.14.2019.10.21.11.23.38 for <ian@sublimesecurity.com> (Google Transport Security); Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
        },
        {
          "name": "Return-Path",
          "position": 15,
          "value": "<joshkamdjou90@gmail.com>"
        },
        {
          "name": "Arc-Authentication-Results",
          "position": 16,
          "value": "i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ehHYOeNl; spf=pass (google.com: domain of joshkamdjou90@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=joshkamdjou90@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com"
        },
        {
          "name": "Arc-Message-Signature",
          "position": 17,
          "value": "i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=; b=gGZe3yO0AYVr+QYSoKCjPrs+7iZauVl0h9FLH/cz/YjelR8e0xJ1w9kJHcjlCigmRd LQX3GVGMdC3O17VMeTeiztsd6OIZHg8pQqQy5exuO5BLm2VnLHoeP8weY+6LVPK7kJiH /KFdZ3S4f7hQrtlxqQWrHTUSAQesPAV0UC+2bUVDUTJGjnDDG/FRumwDpM5q3r284/pK LwLD3Vn9vVuKJJhvNlkrU3sIBGCLSitLjGCAcUwkm0FX9t8bQPAYjN9E8iadIZpIIVU0 XPKc14wQ3RF907FrrwaB8JOiQtKn5SBjbeAWnWXS8DwbEoWIAOpVyXuGrbH6QxEvkALz czmg=="
        },
        {
          "name": "Arc-Seal",
          "position": 18,
          "value": "i=1; a=rsa-sha256; t=1571682219; cv=none; d=google.com; s=arc-20160816; b=UjFMxEI17M6u7hd/V3tM+q/qAYJeKUX6+wZaFWZrXAi/H8RWsiUcBcnPzc8mx1c8d4 q6YIqczF3TEs6wfbbuAgHbel8oAYegOchVgiv0NTgmQsOQ2rzxC2vzyc2ynBdusQUGsv M1TPSJcRHOeimJr5vJA+LDrkKoBhq+Hd8CAqfLycaqnVTK9gWsdP0l2B3phWMGw7a91X KUPVTosgoXRtco/PlfeJbQm9W42S20bOdN/7e8L3T/LbYJ7e0G97/wi7rqzpX9nXoCl3 mOyF84a8HPTMB/hRHjqC5RyrC0no+JeeToDWFMkiYXaZsvEt+4A8L+XWX1a/fNSmj6JG VyBg=="
        }
      ],
      "index": 2,
      "received": "from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id h17sor9568062ilr.14.2019.10.21.11.23.38 for <ian@sublimesecurity.com> (Google Transport Security); Mon, 21 Oct 2019 11:23:39 -0700 (PDT)",
      "signature": {
        "algorithm": "rsa-sha256",
        "body_hash": "A/tRNE/3QQOEOzM/F3H1tLMQfWBKJTRJtWmC+XlE/1g=",
        "domain": "google.com",
        "headers": "to:subject:message-id:date:from:mime-version:dkim-signature",
        "instance": "1",
        "selector": "arc-20160816",
        "signature": "gGZe3yO0AYVr+QYSoKCjPrs+7iZauVl0h9FLH/cz/YjelR8e0xJ1w9kJHcjlCigmRd LQX3GVGMdC3O17VMeTeiztsd6OIZHg8pQqQy5exuO5BLm2VnLHoeP8weY+6LVPK7kJiH /KFdZ3S4f7hQrtlxqQWrHTUSAQesPAV0UC+2bUVDUTJGjnDDG/FRumwDpM5q3r284/pK LwLD3Vn9vVuKJJhvNlkrU3sIBGCLSitLjGCAcUwkm0FX9t8bQPAYjN9E8iadIZpIIVU0 XPKc14wQ3RF907FrrwaB8JOiQtKn5SBjbeAWnWXS8DwbEoWIAOpVyXuGrbH6QxEvkALz czmg==",
        "type": "arc-message"
      }
    },
    {
      "fields": [
        {
          "name": "X-Received",
          "position": 19,
          "value": "by 2002:a05:6e02:a:: with SMTP id h10mr3524960ilr.254.1571682219618; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
        }
      ],
      "index": 3,
      "received": "by 2002:a05:6e02:a:: with SMTP id h10mr3524960ilr.254.1571682219618; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
    },
    {
      "fields": [
        {
          "name": "Received",
          "position": 20,
          "value": "by 2002:a2e:5419:0:0:0:0:0 with SMTP id i25csp4721902ljb; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
        },
        {
          "name": "Delivered-To",
          "position": 21,
          "value": "ian@sublimesecurity.com"
        }
      ],
      "index": 4,
      "received": "by 2002:a2e:5419:0:0:0:0:0 with SMTP id i25csp4721902ljb; Mon, 21 Oct 2019 11:23:39 -0700 (PDT)"
    }
  ]
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
headers.auth_summary.dmarc.passis_null4 rulesmql
coalescefunc_callcoalesce(headers.auth_summary.dmarc.pass)3 rulesmql
ml.nlu_classifier(body.current_thread.text).intentslength_compare03 rulesmql
attachmentslength_compare82 rulesmql
beta.ocr(file.message_screenshot()).textcontainsdocusign2 rulesmql
beta.ocr(file.message_screenshot()).textregex_matchDokument (überprüfen|prüfen|unterschreiben|geschickt)2 rulesmql
beta.ocr(file.message_screenshot()).textregex_matchimportant edocs2 rulesmql
body.current_thread.textcontainsdocument portal2 rulesmql
body.current_thread.textlength_compare1002 rulesmql
body.html.rawregex_match((<br\s*/?>\s*){20,}|\n{20,})2 rulesmql
body.html.rawregex_match(<p class=".*?"><span style=".*?"><o:p>&nbsp;</o:p></span></p>\s*){30,}2 rulesmql
body.html.rawregex_match(<p>&nbsp;</p>\s*){7,}2 rulesmql
body.html.rawregex_match(<p[^>]*>&nbsp;</p>\s*){7,}2 rulesmql
body.html.rawregex_match(<p[^>]*>\s*&nbsp;<br>\s*</p>\s*){5,}2 rulesmql
body.html.rawregex_match(<p[^>]*>\s*<br\s*/?>\s*</p>\s*){30,}2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.ips (collection)

#

Description

Message Data Model attribute: headers.ips

Fields #

NameDescription
ipThe IP in canonical form

Example Message Record #

{
  "headers.ips": [
    {
      "ip": "127.0.0.1"
    },
    {
      "ip": "185.243.112.105"
    },
    {
      "ip": "216.71.148.252"
    },
    {
      "ip": "10.13.177.157"
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.reply_to (collection)

#

Description

Message Data Model attribute: headers.reply_to

Fields #

NameDescription
display_nameDisplay name
email.domain
email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
email.domain.root_domainThe root domain, including the TLD
email.domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
email.domain.validWhether the domain is valid
email.emailFull email address
email.local_partLocal-part, i.e. before the @

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
headers.reply_tolength_compare031 rulesmql
headers.auth_summary.dmarc.passeqtrue12 rulesmql
headers.auth_summary.spf.passeqtrue12 rulesmql
beta.profile.by_reply_tofunc_callbeta.profile.by_reply_to().prevalence == new5 rulesmql
network.whoisfunc_callnetwork.whois(sender.email.domain).days_old <= 303 rulesmql
sender.email.domain.root_domaineqdocusign.net3 rulesmql
sender.email.emaileqno-reply@zoom.us3 rulesmql
body.current_thread.textcontains (kindly 2 rulesmql
body.current_thread.textcontains anyone you know 2 rulesmql
body.current_thread.textcontains downsizing 2 rulesmql
body.current_thread.textcontains free donation2 rulesmql
body.current_thread.textcontains generously offering 2 rulesmql
body.current_thread.textcontains if you will take it 2 rulesmql
body.current_thread.textcontains indicate your interest 2 rulesmql
body.current_thread.textcontains kindly 2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.return_path

#

Description

Message Data Model attribute: headers.return_path

Fields #

NameDescription
domain
domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
domain.root_domainThe root domain, including the TLD
domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
emailFull email address
local_partLocal-part, i.e. before the @

Example Message Record #

{
  "headers.return_path": {
    "domain": {
      "domain": "vps.server.com",
      "root_domain": "server.com",
      "sld": "server",
      "subdomain": "vps",
      "tld": "com",
      "valid": true
    },
    "email": "root@vps.server.com",
    "local_part": "root"
  }
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
headers.return_path.domain.domaincross_field_comparesender.email.domain.domain2 rulesmql
headers.return_path.domain.domaineqsendgrid.net3 rulesmql
headers.return_path.domain.domainnecalendar-server.bounces.google.com2 rulesmql
headers.auth_summary.spf.details.designatorcontains+srs=2 rulesmql
headers.return_path.domain.root_domaineqsalesforce.com2 rulesmql
headers.return_path.domain.root_domainnebestdeals.today2 rulesmql
headers.return_path.emailcross_field_comparesender.email.email2 rulesmql
headers.return_path.emailis_not_null2 rulesmql
headers.return_path.local_partcontains+srs=2 rulesmql
network.whoisfunc_callnetwork.whois(sender.email.domain).days_old <= 302 rulesmql
sender.email.domain.root_domainnebestdeals.today2 rulesmql
subject.subjectregex_matchremittance2 rulesmql
subject.subjectregex_matchw22 rulesmql
beta.ocr(file.message_screenshot()).textcontainsbest buy1 rulemql
beta.ocr(file.message_screenshot()).textcontainsebay1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.x_authenticated_domain

#

Description

Message Data Model attribute: headers.x_authenticated_domain

Fields #

NameDescription
domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.x_authenticated_sender

#

Description

Message Data Model attribute: headers.x_authenticated_sender

Fields #

NameDescription
emailFull email address

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #

headers.x_originating_ip

#

Description

Message Data Model attribute: headers.x_originating_ip

Fields #

NameDescription
ipThe IP in canonical form

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
headers.mailerstarts_withOpen-Xchange Mailer1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #