Blue Lantern Security email monitoring connects to Google Workspace or Microsoft 365 once, at the organization level, and analyzes every new message in each monitored mailbox within seconds of arrival. Findings land in one Monitoring Hub with a Clean, Suspicious, or Malicious verdict, and malicious mail can be moved to Spam or Junk automatically. Nothing is installed on user machines.
Access: included with a Seat License at $15 per monitored user per month. Requires a Google Workspace domain or a Microsoft 365 tenant and an administrator to grant access. Personal Outlook.com and Hotmail mailboxes can be monitored on a single-seat personal account. See current pricing.
Native spam filters stop most junk. The messages that reach an inbox are the ones that got through, and one clicked link is enough. Email monitoring gives every monitored mailbox a second, independent analysis of each message, and gives you one place to see what your team is receiving.
What does email monitoring check?
Each monitored message runs through the same Email Threat Analyzer used for on-demand checks. The report is a set of pass/fail findings with evidence.
| Area | What is checked |
|---|---|
| Authentication | SPF, DKIM, and DMARC results and whether they align with the visible From domain |
| Sender | From and Reply-To mismatches, misleading display names, sender spoofing, and lookalike domains |
| Links | Malicious destinations, URL shorteners, mismatched link text, and lookalike domains |
| Attachments | File types associated with executable content, including Office macros and scripted PDFs |
| Content | Urgency patterns, suspicious keywords, hidden content, and scripts |
| Domain context | Sender domain age and sender/recipient-domain relationships |
For a walkthrough of a real report, including a message that passed SPF and DKIM and still deserved attention, read how to read a suspicious email report.
How does it connect?
| Platform | How it works | Optional action |
|---|---|---|
| Google Workspace | A service account you own, with domain-wide delegation you grant, reads monitored mailboxes through the Gmail API. Gmail pushes new-mail notifications through your own Pub/Sub topic | Move malicious mail to Spam (adds one write scope) |
| Microsoft 365 | An app registration you own, with application permissions you consent to, reads monitored mailboxes through Microsoft Graph. Change notifications push new mail as it lands | Auto-quarantine malicious mail to Junk Email (adds one write permission) |
| Outlook.com / Hotmail (personal) | One Microsoft sign-in with read-only inbox access | None; read-only, inbox only |
Setup is guided by a wizard in the app, with every value shown copy-ready. On Microsoft 365, the wizard also generates the PowerShell for an Exchange Application Access Policy that limits the credential to a mail-enabled security group of the mailboxes you want monitored. The connection is validated live before anything is stored.
Users pulled from your directory are seated up to the number of seats you purchased. Unseated mailboxes are not ingested.
What happens when something is flagged?
- Every scan appears in the Monitoring Hub with its verdict, target mailbox, and a link to the full report. Admins see the whole organization and can filter by submitter, verdict, or time range.
- Alert rules deliver matches by email or as JSON to an HTTPS endpoint such as a Splunk HTTP Event Collector, a SIEM, or a webhook. Rules can fire immediately per matching run, or as an hourly or daily digest.
- Automatic filing is optional. If you enable it, messages with a Malicious verdict are moved to Spam (Gmail) or Junk Email (Microsoft 365). Nothing is ever deleted or sent on your behalf. Leave it off for strictly read-only monitoring.
- Duplicates collapse. An inbox copy and a user-forwarded copy of the same message dedupe to one report.
Other ways to get a message analyzed
Organization-wide monitoring covers mail as it arrives. For messages users want a second opinion on, Blue Lantern Security also offers:
- An Outlook add-in and a self-deployed Gmail add-on that submit the open message to the Email Threat Analyzer in one click.
- A forwarding mailbox: forward the original message as an
.emlattachment to the address shown in the app. - The web upload described on Is This Email a Scam?, free for 30 runs a day.
- The REST API for SOAR playbooks and automation, included with a Seat License. See automating email analysis through the API.
How Blue Lantern Security makes email analysis accessible compares these submission paths.
What data does Blue Lantern Security keep?
Raw message payloads are deleted within 24 hours. Analysis reports are retained for 7 days and are accessible only to your account. The deduplication cache stores a content hash and run reference, never message content. Push notifications from Google and Microsoft carry no mail content, only a mailbox address and a change cursor, and every notification is verified before it is accepted.
Permissions are read-only unless you explicitly enable the spam-move or quarantine action. A Workspace super admin or Entra ID administrator can revoke access at any time, which severs the connection immediately. Review the Privacy Policy for full retention terms.
Common questions
Does this replace my spam filter or secure email gateway?
No. Google and Microsoft filtering keeps running as before. Email monitoring analyzes the mail that reaches the inbox and gives you evidence and alerts on what got through.
Do users have to install anything?
No. The organization integrations read mailboxes through the provider's API. The optional Outlook add-in and Gmail add-on exist only for one-click manual submissions.
Can a phishing email pass SPF, DKIM, and DMARC?
Yes. Authentication establishes who was authorized to send, not whether the request is honest. A compromised account or an attacker-owned domain can send authenticated mail, which is why the report also examines sender, links, attachments, and content. Microsoft explains email authentication.
How quickly is a new message analyzed?
Within seconds of arrival. Google and Microsoft push a notification when new mail lands, and the message is analyzed as soon as the notification is received.
Can I monitor only some mailboxes?
Yes. On Microsoft 365, you choose a mail-enabled security group and can enforce an Application Access Policy so the credential cannot reach mailboxes outside it. On Google Workspace, users are seated up to your purchased seat count, and unseated mailboxes are not ingested.
What else can the integration monitor?
The same Gmail and Microsoft 365 integrations offer optional daily scans that you enable with a checkbox: identity posture (MFA coverage and dormant accounts), email configuration (SPF, DKIM, DMARC, external forwarding, and suspicious inbox rules), and AI exposure (which third-party and AI apps hold access to your data).
Related guides
- Is This Email a Scam? Analyze one suspicious message
- How to read a suspicious email report
- Best tools to analyze a suspicious email
- How to get started with small business security
- Monitor your email configuration