For AI agents: visit https://docs.sublime.security/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI.
Jump to Content
Sublime Security
DocumentationAPI ReferenceProduct Releases
Log InSublime Security
Documentation
Log In
DocumentationAPI ReferenceProduct Releases

Getting Started

  • Overview

Install Sublime

  • Installation Options
  • Sublime Cloud
  • Docker
    • Docker Install
    • Docker Requirements and Limitations
    • Docker Troubleshooting
  • Amazon AWS
    • AWS CloudFormation Install
    • AWS GovCloud Install
    • Custom Domains
  • Microsoft Azure
    • Microsoft Azure ARM Install

Manage Sublime

  • Add Email/Message Sources
    • Microsoft 365
      • Sublime Cloud - Microsoft 365
      • Self Managed - Microsoft 365
    • How to update permission settings to enable automatic deletion of calendar events
    • Google Workspace
      • Sublime Cloud - Google Workspace
      • Self Managed - Google Workspace
    • IMAP
  • Configure "Report Phishing"
    • Add your abuse mailbox
    • Microsoft 365 Configure “Report Phishing”
    • Gmail Configure "Report Phishing"
  • Configure "Quarantine Digests"
  • Access & Authentication
    • Single Sign-On (SSO) Configuration
      • Okta
      • Entra ID (Azure)
      • Google
    • Role-Based Access Control (RBAC)
    • Message Access Controls
  • Export to S3
    • Export Message MDMs
    • Export Audit Logs and Message Events
  • Email Data Loss Prevention (DLP) Public Beta
  • Inline Protection for Inbound Messages
  • IP Authentication Override

Use Sublime

  • Message types
  • Message groups
  • MQL Detection Rules
    • Attack Surface Reduction
    • Rule Severity
    • Rule Feeds
      • Rules file format (YAML)
      • Private rule feed authentication
    • YARA
    • Using the MQL Editor
  • Automations
    • Auto-respond to User Reports
  • Actions
    • Quarantine
    • Trash
    • Warning Banners
    • Move to Spam
    • Auto-review
    • Track Link Clicks
    • Webhook
      • Tines Webhook
    • Email Alert
    • Email Alert with EML Attached
    • Slack Alert
    • Move to Promotions
  • Lists
    • Configure the org_vips list
    • Configure Link Analysis exclusion lists
    • Google Workspace - Configure Permissions to Sync Organizational Units (OUs)
  • Exclusions
  • Attack Score
  • ASA: Autonomous Security Analyst
  • ADÉ: Autonomous Detection Engineer
  • Email bomb protection
  • Multi-Tenancy Management

Tutorials

  • MQL Guides
    • How to use message header values in a rule
    • How to detect manual outbound forwards
    • How to detect text in attachments
    • How to detect lookalike domains
    • How to detect keywords or phrases in the body content of messages

Reference

  • Message Data Model (MDM)
  • Message Query Language (MQL)
    • Syntax
    • Missing or null values
    • Functions
    • Strings functions
    • RegEx functions
    • Enrichment functions
    • Common snippets
  • Metrics Collection in Self-Hosted Deployments

How-to Guides

  • Mimecast Migration Guide
  • Proofpoint Migration Guide

Add Email/Message Sources

Connect your Sublime Platform instance to one or more email/message sources:

Add a Microsoft 365 message source
Add a Google Workspace message source
Add an IMAP message source

Updated 6 months ago


What’s Next

Add a message source

  • Microsoft 365
  • IMAP
  • Google Workspace