Mail Streams
What it does
Define capture rules based on symbols, scores, or header patterns. Stream entries appear in the Mail Streams viewer with full message detail: decoded body, MIME structure, headers, and scan results.
The Ask LLM panel sends the captured message to your chosen model with a curated preset or custom prompt. Responses are cached so repeat lookups are instant.
What question it answers
Show me all the messages my classifier got wrong. What does this phishing campaign look like? Why is this sender hitting my custom rule?
Streams let you curate investigation queues. The LLM integration accelerates analysis: explain the verdict, classify the pattern, suggest improvements.
LLM integration
The Ask LLM panel offers curated presets — explain a verdict, explain a suspected false positive, surface a missed-spam signal, or suggest a rule — plus custom prompts. The model receives only the decoded message and its scan results, never raw payloads.

Example: Phishing campaign analysis
An operator defines a stream catching messages that combine freemail senders with suspicious URLs. The stream fills with 200 entries from a single sender domain. Opening one entry and clicking Ask LLM with the 'Is this a known phishing kit?' prompt returns an analysis identifying the kit variant and suggesting header patterns for a new composite rule.




