What is threat intelligence?

StepDescription
1. Publish SPF and DKIM recordsDefine which email servers are authorized to send emails on behalf of the domain
2. Publish DMARC policySet a policy to instruct recipient servers how to handle unauthenticated emails (none, quarantine, reject)
3. Receive reportsCollect aggregate and forensic reports from recipient servers detailing authentication results
4. Analyze reportsUse threat intelligence tools built into the Sendmarc platform to interpret data, identify threats, and adjust policies accordingly
5. Enforce policyGradually move from monitoring (none) to enforcement (quarantine or reject) to defend against spoofing

Benefits of threat intelligence for email security


Sendmarc’s threat intelligence platform


Threat intelligence FAQs

What is threat intelligence?

Threat intelligence is the process of gathering, analyzing, and acting on information about cyberthreats. It helps organizations understand and defend against cyberattacks.

What is a threat intelligence platform?

A threat intelligence platform is a tool that automates the collection, analysis, and reporting of threat data. Some platforms also provide actionable insights and alerts to security teams.

How do I perform threat intelligence?

Performing threat intelligence involves collecting relevant data, such as Domain-based Message Authentication, Reporting, and Conformance (DMARC) reports. It then requires data analysis to identify suspicious patterns and take proactive measures to defend against identified threats.

What are the five stages of threat intelligence?

The five stages of threat intelligence are:

  1. Planning and direction: Defining intelligence requirements and objectives
  2. Collection: Gathering raw data from various sources
  3. Processing: Organizing and filtering data for analysis
  4. Analysis: Interpreting data to produce actionable insights
  5. Dissemination: Sharing intelligence with stakeholders for informed decision-making