Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion public/__redirects
Original file line number Diff line number Diff line change
Expand Up @@ -2435,7 +2435,7 @@
/cloudflare-one/email-security/detection-settings/trusted-domains/ /cloudflare-one/email-security/settings/trusted-domains/ 301
/cloudflare-one/email-security/settings/detection-settings/impersonation-registry/* /cloudflare-one/email-security/settings/impersonation-registry/:splat 301
/cloudflare-one/email-security/detection-settings/* /cloudflare-one/email-security/settings/detection-settings/:splat 301

/cloudflare-one/email-security/reference/domain-information/ /cloudflare-one/email-security/settings/domain-management/domain/ 301

# Learning paths

Expand Down
Original file line number Diff line number Diff line change
@@ -1,24 +1,24 @@
---
title: Use Logpush for Email Security user actions
description: Send user action logs for Email Security to an endpoint of your choice with Cloudflare Logpush.
title: Use Logpush for Email security user actions
description: Send user action logs for Email security to an endpoint of your choice with Cloudflare Logpush.
date: 2024-11-07T23:22:49Z
---

You can now send user action logs for Email Security to an endpoint of your choice with Cloudflare Logpush.
You can now send user action logs for Email security to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set or select from multiple fields you want to send. For all users, we will log the date and time, user ID, IP address, details about the message they accessed, and what actions they took.
Filter logs matching specific criteria you have set or select from multiple fields you want to send. For all users, we will log the date and time, user ID, IP address, details about the message they accessed, and what actions they took.

When creating a new Logpush job, remember to select **Audit logs** as the dataset and filter by:
When creating a new Logpush job, remember to select **Audit logs** as the dataset and filter by:

- **Field**: `"ResourceType"`
- **Operator**: `"starts with"`
- **Value**: `"email_security"`.
- **Value**: `"email_security"`.

![Logpush-user-actions](~/assets/images/changelog/email-security/Logpush-User-Actions.png)

For more information, refer to [Enable user action logs](/cloudflare-one/insights/logs/enable-logs/#enable-user-action-logs).
For more information, refer to [Enable user action logs](/cloudflare-one/insights/logs/enable-logs/#enable-user-action-logs).

This feature is available across all Email Security packages:
This feature is available across all Email security packages:

- **Enterprise**
- **Enterprise + PhishGuard**
- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
Expand Up @@ -4,16 +4,16 @@ description: Escalate user-submitted messages for reclassification by the Cloudf
date: 2024-12-19T23:22:49Z
---

After you triage your users' submissions (that are machine reviewed), you can now escalate them to our team for reclassification (which are instead human reviewed). User submissions from the submission alias, PhishNet, and our API can all be escalated.
After you triage your users' submissions (that are machine reviewed), you can now escalate them to our team for reclassification (which are instead human reviewed). User submissions from the submission alias, PhishNet, and our API can all be escalated.

![Escalate](~/assets/images/changelog/email-security/Escalate.png)

From **Reclassifications**, go to **User submissions**. Select the three dots next to any of the user submissions, then select **Escalate** to create a team request for reclassification. The Cloudflare dashboard will then show you the submissions on the **Team Submissions** tab.
From **Reclassifications**, go to **User submissions**. Select the three dots next to any of the user submissions, then select **Escalate** to create a team request for reclassification. The Cloudflare dashboard will then show you the submissions on the **Team Submissions** tab.

Refer to [User submissions](/cloudflare-one/email-security/reclassifications/user-submissions/) to learn more about this feature.
Refer to [User submissions](/cloudflare-one/email-security/reclassifications/user-submissions/) to learn more about this feature.

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**
- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,8 @@ import { Render } from "~/components";

You now have more transparency about team and user submissions for phishing emails through a **Reclassification** tab in the Zero Trust dashboard.

Reclassifications happen when users or admins [submit a phish](/cloudflare-one/email-security/settings/phish-submissions/) to Email Security. Cloudflare reviews and - in some cases - reclassifies these emails based on improvements to our machine learning models.
Reclassifications happen when users or admins [submit a phish](/cloudflare-one/email-security/settings/phish-submissions/) to Email security. Cloudflare reviews and - in some cases - reclassifies these emails based on improvements to our machine learning models.

This new tab increases your visibility into this process, allowing you to view what submissions you have made and what the outcomes of those submissions are.

![Use the Reclassification area to review submitted phishing emails](~/assets/images/changelog/email-security/reclassifications-tab.png)
![Use the Reclassification area to review submitted phishing emails](~/assets/images/changelog/email-security/reclassifications-tab.png)
Original file line number Diff line number Diff line change
@@ -1,27 +1,27 @@
---
title: Check status of Email Security or Area 1
description: Check the operational status of Email Security and Area 1 on the Cloudflare Status page.
title: Check status of Email security or Area 1
description: Check the operational status of Email security and Area 1 on the Cloudflare Status page.
date: 2025-02-27T23:22:49Z
---

Concerns about performance for Email Security or Area 1? You can now check the operational status of both on the [Cloudflare Status page](https://www.cloudflarestatus.com/).
Concerns about performance for Email security or Area 1? You can now check the operational status of both on the [Cloudflare Status page](https://www.cloudflarestatus.com/).

For Email Security, look under **Cloudflare Sites and Services**.
For Email security, look under **Cloudflare Sites and Services**.

- **Dashboard** is the dashboard for Cloudflare, including Email Security
- **Email Security (Zero Trust)** is the processing of email
- **API** are the Cloudflare endpoints, including the ones for Email Security
- **Dashboard** is the dashboard for Cloudflare, including Email security
- **Email security (Zero Trust)** is the processing of email
- **API** are the Cloudflare endpoints, including the ones for Email security

For Area 1, under **Cloudflare Sites and Services**:

- **Area 1 - Dash** is the dashboard for Cloudflare, including Email Security
- **Email Security (Area1)** is the processing of email
- **Area 1 - API** are the Area 1 endpoints
- **Area 1 - Dash** is the dashboard for Cloudflare, including Email security
- **Email security (Area1)** is the processing of email
- **Area 1 - API** are the Area 1 endpoints

![Status-page](~/assets/images/changelog/email-security/Status-Page.png)

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**
- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ From **Investigation**, go to **View details**, and look for the **Links identif

For more details, refer to [Open links](/cloudflare-one/email-security/monitoring/search-email/#open-links).

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,11 +4,11 @@ description: Quickly deploy a free Email DLP solution for Microsoft 365 environm
date: 2025-02-25T23:22:49Z
---

Cloudflare Email Security customers who have Microsoft 365 environments can quickly deploy an Email DLP (Data Loss Prevention) solution for free.
Cloudflare Email security customers who have Microsoft 365 environments can quickly deploy an Email DLP (Data Loss Prevention) solution for free.

Simply deploy our add-in, create a DLP policy in Cloudflare, and configure Outlook to trigger behaviors like displaying a banner, alerting end users before sending, or preventing delivery entirely.
Simply deploy our add-in, create a DLP policy in Cloudflare, and configure Outlook to trigger behaviors like displaying a banner, alerting end users before sending, or preventing delivery entirely.

Refer to [Outbound Data Loss Prevention](/cloudflare-one/email-security/outbound-dlp/) to learn more about this feature.
Refer to [Outbound Data Loss Prevention](/cloudflare-one/email-security/outbound-dlp/) to learn more about this feature.

In GUI alert:

Expand All @@ -22,7 +22,7 @@ Prevent delivery:

![DLP-Blocked](~/assets/images/changelog/email-security/DLP-Blocked.png)

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Enterprise**
- **Enterprise + PhishGuard**
- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
---
title: Use Logpush for Email Security detections
title: Use Logpush for Email security detections
description: Send detection logs to an endpoint of your choice with Cloudflare Logpush.
date: 2025-03-01T23:22:49Z
---

You can now send detection logs to an endpoint of your choice with Cloudflare Logpush.
You can now send detection logs to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set and select from over 25 fields you want to send. When creating a new Logpush job, remember to select **Email security alerts** as the dataset.
Filter logs matching specific criteria you have set and select from over 25 fields you want to send. When creating a new Logpush job, remember to select **Email security alerts** as the dataset.

![logpush-detections](~/assets/images/changelog/email-security/Logpush-Detections.png)

For more information, refer to [Enable detection logs](/cloudflare-one/insights/logs/enable-logs/#enable-detection-logs).
For more information, refer to [Enable detection logs](/cloudflare-one/insights/logs/enable-logs/#enable-detection-logs).

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Enterprise**
- **Enterprise + PhishGuard**
- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
@@ -1,20 +1,20 @@
---
title: CASB and Email Security
description: Get two free CASB integrations with your Email Security subscription.
title: CASB and Email security
description: Get two free CASB integrations with your Email security subscription.
date: 2025-04-01T23:22:49Z
---

With Email Security, you get two free CASB integrations.
With Email security, you get two free CASB integrations.

Use one SaaS integration for Email Security to sync with your directory of users, take actions on delivered emails, automatically provide EMLs for reclassification requests for clean emails, discover CASB findings and more.
Use one SaaS integration for Email security to sync with your directory of users, take actions on delivered emails, automatically provide EMLs for reclassification requests for clean emails, discover CASB findings and more.

With the other integration, you can have a separate SaaS integration for CASB findings for another SaaS provider.

Refer to [Add an integration](/cloudflare-one/integrations/cloud-and-saas/#add-an-integration) to learn more about this feature.

![CASB-EmailSecurity](~/assets/images/changelog/email-security/CASB-EmailSecurity.png)

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Open email attachments with Browser Isolation
description: A new attachment section in Email Security allows you to safely open attachments to view and investigate.
description: A new attachment section in Email security allows you to safely open attachments to view and investigate.
date: 2025-05-15T23:22:49Z
---

Expand All @@ -19,8 +19,8 @@ For more details, refer to our [setup guide](/cloudflare-one/remote-browser-isol

Some attachment types may not render in Browser Isolation. If there is a file type that you would like to be opened with Browser Isolation, reach out to your Cloudflare contact.

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ To use this feature, you must:

For more details, refer to our [setup guide](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/).

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ For example, you may want to deliver suspicious messages but isolate the links f

To isolate all links within a message based on the disposition, select **Settings** > **Link Actions** > **View** and select **Configure**. As with other other links you isolate, an interstitial will be provided to warn users that this site has been isolated and the link will be recrawled live to evaluate if there are any changes in our threat intel. Learn more about this feature on [Configure link actions](https://developers.cloudflare.com/cloudflare-one/email-security/settings/detection-settings/configure-link-actions/).

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Enterprise**
- **Enterprise + PhishGuard**
Original file line number Diff line number Diff line change
@@ -1,25 +1,25 @@
---
title: Updated Email Security roles
description: More granular controls for Email Security roles
title: Updated Email security roles
description: More granular controls for Email security roles
date: 2025-09-01T23:25:49Z
---

To provide more granular controls, we refined the [existing roles](/cloudflare-one/roles-permissions/#email-security-roles) for Email Security and launched a new Email Security role as well.
To provide more granular controls, we refined the [existing roles](/cloudflare-one/roles-permissions/#email-security-roles) for Email security and launched a new Email security role as well.

All Email Security roles no longer have read or write access to any of the other Zero Trust products:
All Email security roles no longer have read or write access to any of the other Zero Trust products:

- **Email Configuration Admin**
- **Email Integration Admin**
- **Email Security Read Only**
- **Email Security Analyst**
- **Email Security Policy Admin**
- **Email Security Reporting**
- **Email security Read Only**
- **Email security Analyst**
- **Email security Policy Admin**
- **Email security Reporting**

To configure [Data Loss Prevention (DLP)](/cloudflare-one/email-security/outbound-dlp/) or [Remote Browser Isolation (RBI)](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/#set-up-clientless-web-isolation), you now need to be an admin for the Zero Trust dashboard with the **Cloudflare Zero Trust** role.

Also through customer feedback, we have created a new additive role to allow **Email Security Analyst** to create, edit, and delete Email Security policies, without needing to provide access via the **Email Configuration Admin** role. This role is called **Email Security Policy Admin**, which can read all settings, but has write access to [allow policies](/cloudflare-one/email-security/settings/detection-settings/allow-policies/), [trusted domains](/cloudflare-one/email-security/settings/detection-settings/trusted-domains/), and [blocked senders](/cloudflare-one/email-security/settings/detection-settings/blocked-senders/).
Also through customer feedback, we have created a new additive role to allow **Email security Analyst** to create, edit, and delete Email security policies, without needing to provide access via the **Email Configuration Admin** role. This role is called **Email security Policy Admin**, which can read all settings, but has write access to [allow policies](/cloudflare-one/email-security/settings/detection-settings/allow-policies/), [trusted domains](/cloudflare-one/email-security/settings/detection-settings/trusted-domains/), and [blocked senders](/cloudflare-one/email-security/settings/detection-settings/blocked-senders/).

This feature is available across these Email Security packages:
This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,27 +4,34 @@ description: Customers can now choose their preferred mail processing location t
date: 2025-09-11T23:15:00Z
---

We’re excited to announce that Email Security customers can now choose their preferred mail processing location directly from the UI when onboarding a domain. This feature is available for the following onboarding methods: **MX**, **BCC**, and **Journaling**.
We’re excited to announce that Email security customers can now choose their preferred mail processing location directly from the UI when onboarding a domain. This feature is available for the following onboarding methods: **MX**, **BCC**, and **Journaling**.

### What’s new
Customers can now select where their email is processed. The following regions are supported:
- **Germany**
- **India**
- **Australia**

Global processing remains the default option, providing flexibility to meet both compliance requirements or operational preferences.
Customers can now select where their email is processed. The following regions are supported:

- **Germany**
- **India**
- **Australia**

Global processing remains the default option, providing flexibility to meet both compliance requirements or operational preferences.

### How to use it
When onboarding a domain with MX, BCC, or Journaling:
1. Select the desired processing location (Germany, India, or Australia).
2. The UI will display updated processing addresses specific to that region.
3. For MX onboarding, if your domain is managed by Cloudflare, you can automatically update MX records directly from the UI.

When onboarding a domain with MX, BCC, or Journaling:

1. Select the desired processing location (Germany, India, or Australia).
2. The UI will display updated processing addresses specific to that region.
3. For MX onboarding, if your domain is managed by Cloudflare, you can automatically update MX records directly from the UI.

### Availability
This feature is available across these Email Security packages:
- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**

This feature is available across these Email security packages:

- **Advantage**
- **Enterprise**
- **Enterprise + PhishGuard**

### What’s next
We’re expanding the list of processing locations to match our [Data Localization Suite (DLS)](/data-localization/) footprint, giving customers the broadest set of regional options in the market without the complexity of self-hosting.

We’re expanding the list of processing locations to match our [Data Localization Suite (DLS)](/data-localization/) footprint, giving customers the broadest set of regional options in the market without the complexity of self-hosting.
Loading
Loading