Security engineers encounter the need to set up a phishing mailbox for reports within their organization all the time. Traditional email filters help, but they're never 100% accurate, and when suspicious emails slip through, there's real risk that a user clicks a malicious link or falls for a social engineering attempt. Most organizations tell users to forward anything suspicious to a dedicated inbox, where the security team helps determine whether it's legitimate or malicious.
The problem? Security teams then have to actively manage that inbox on top of their existing workload. Naturally, many build SOAR workflows to automate analysis, only to find themselves maintaining an automation pipeline on top of their day jobs.
Blue Lantern Security is designed to solve exactly this.
How Blue Lantern Enables Flexible Email Submission for Analysis
One of our core goals at Blue Lantern Security is to make security analysis as accessible as possible, while minimizing the operational burden on your team. We support four submission methods so you can work the way your organization already works:
Through the UI - The most straightforward option: drag, drop, and submit. Great for getting started or handling one-off investigations, though most teams move toward the more integrated methods once they're up and running.
Through the API - The right choice if you're building or enhancing a SOAR workflow. Submit email data and receive detailed analysis results quickly, enabling automated downstream decisions without manual intervention.
Through a mailbox add-on. We offer dedicated add-ons for Outlook and Gmail that let users submit suspicious emails directly to Blue Lantern Security with a single click. No context-switching required. An API key is needed to connect the add-on to your account.
Through Blue Lantern Security's forwarding mailbox. Sign in to the Email Analyzer and use the account-specific instructions under alternative submission methods. Forward the original message as an
.emlattachment, rather than an inline forward. Routing and permissions depend on the account. The Email Threat Analyzer documentation explains the workflow, including the separate static malware analysis associated with mailbox submissions.
Meeting Your Team Where You Are
Whether you want full control through custom automations, a lightweight manual process, or to delegate analysis entirely to our phishing inbox, Blue Lantern Security is built to fit your workflow, not the other way around.
We're always open to feedback. If you have suggestions or ideas for new submission methods, reach out at [email protected].
Want to go deeper?
- Automate email analysis through our API
- How we compare to VirusTotal and MXToolbox
- Why deterministic tools sometimes beat modern AI models
Current access and a one-message starting point
The web free tier includes 30 daily runs shared across Email Analyzer, URL Threat Analyzer and Static Malware Analyzer. API access and monitoring require a paid seat; check current pricing and the app's instructions for the submission method you choose.
For file requirements, privacy and interpretation, start with Is This Email a Scam?. Compare workflows in Best Tools to Analyze a Suspicious Email.