Threat intelligence

Global Email & Malware Threat Intelligence

Explore reported spam sources and malicious infrastructure around the world.

Private beta

Availability, stated plainly: no intelligence source is enabled on this deployment, so there is nothing to draw yet. The page below explains what the map would show, what it would not, and shows an empty state instead of a picture of nothing dressed up as data.

The map

Nothing to draw yet

No intelligence source is enabled on this deployment, so the map holds no indicators. Every source it can read is switched off, and one of them — the spam-source layer — is switched off because the data license needed to fill it is not one we hold.

Rather than render a world outline with zeros on it, or a screenshot of numbers from somewhere else, this space stays empty until there is something in it. An empty map that says it is empty is information; a map with invented data on it is not.

The map itself is the part still being built. When a source is enabled it draws here, on this page, at this heading.

How to read it, once there is something to read

Four things have to be said before anybody looks at a country shaded darker than its neighbors, because all four are ways a map like this gets misread:

  • Locations reflect observed infrastructure, not the people responsible. An address in a country means a machine was reported there. It says nothing about who rented it, who is operating it, or where they are. Most of this infrastructure is compromised or rented by someone who is somewhere else.
  • Coverage varies by source. Each source watches what it watches, in the regions and formats it watches them in. A country that looks quiet may be quiet, or may be somewhere no enabled source reports from. The map cannot tell those apart, so neither should you.
  • These indicators do not represent global email volume. Nothing here is a measurement of how much mail any country sends, or how much of it is spam. It is a count of reported infrastructure, which is a different quantity entirely.
  • These indicators are not MailThreatZero customer detections. They are other people's published observations, shown to anonymous visitors. No customer's mail, no protected domain's traffic, and no verdict this gateway reached about a real message contributes a single point to this map. Keeping those apart is deliberate: mixing them would put customer-derived data on a public page and produce a headline number nobody could later take apart.

What the number means

One metric, defined once so that nothing downstream can quietly redefine it:

Unique reported infrastructure IPs — the number of distinct public IP addresses attributed to a country within a time window, counted once across every source that is both enabled and permitted to be displayed.

Four consequences follow from that sentence, and each one is a mistake it prevents:

  • Several indicators may reference one address. Sources report different things: one reports indicators of compromise, another reports URLs. Twenty reported URLs on one host are one address on this map, not twenty. Adding a URL count to an address count does not produce a quantity at all, and it is the easiest possible way to publish a figure that is wrong by a factor of three.
  • One address is not one villain. Shared hosting is the normal case. A single address can carry a company's website, somebody's mail server and a malicious path at the same time, and the report is about the path rather than about the machine or its other tenants.
  • Category totals overlap and need not sum. One address can be a botnet controller and a malware host at once. Each category count is correct on its own and their sum is larger than the combined total — so a stacked chart built on the assumption that they add up would be wrong, and nobody would notice.
  • Public addresses only. Private, loopback, link-local, multicast, reserved and carrier-NAT ranges are refused before they are stored. A public map plotting a private range is leaking somebody's internal layout, and one plotting a carrier's NAT pool is plotting a carrier rather than an attacker.

An address that no geolocation database can place is counted as unmapped and reported as such, rather than being dropped. Silently discarding it would make the total quietly smaller than reality with nothing anywhere saying so.

Three layers, kept separate

The layers are labeled separately because they are different claims, and a single merged "threats" number would hide which one an address belongs to. None of them has any data on this deployment today.

Spam sources

No source

Addresses reported as sending unsolicited mail. This layer is empty and cannot be filled from what is available to us: the one source that publishes it does so under terms that cover reputation lookups rather than bulk data, and we do not hold the data access that would permit it. Nothing else here is ever relabeled as spam to fill the gap.

Malware hosting

No source

Addresses reported as serving malicious payloads — the download at the end of a link, rather than the mail that carried it. Two sources can populate this layer and both are switched off.

Command-and-control

No source

Addresses reported as the place already-infected machines report back to. A category is taken from each individual record, never assumed from the name of the feed it arrived in, and a threat type that is not recognized is counted as unmapped rather than guessed at.

How this map works

  1. Sources are read, not crawled. Records are fetched from each source's published interface. Nothing fetches a malicious URL, resolves it for content, follows a redirect or downloads a sample. A reported URL stays a string. The one outbound lookup that touches an indicator's own infrastructure is a DNS resolution, which is paced, timestamped, and recorded as current hosting rather than as historical origin.
  2. Records are normalized and rejected loudly. Malformed rows are the normal case at this scale, so rejections are counted with their reasons. A feed that silently halves itself looks exactly like a quiet feed, and the count is what tells a schema change apart from a slow day.
  3. Addresses are placed by country using a GeoIP database, and each address is attributed to one country — the one given by the most recent record mentioning it. Without that rule, two sources disagreeing would put one address in two countries and the per-country numbers would stop summing to the total.
  4. Two questions are answered separately. "Who was reported during this window" is a historical statement and never changes retroactively. "Who is on a list right now" changes as records expire or stop appearing in a source's latest snapshot — which is how a delisting is detected at all, because most sources do not send removals, they simply stop including the record. Publishing only one of those would overstate the present or erase the past.
  5. Aggregates are replaced atomically. A visitor reads either the previous complete set or the new one, never a half-built map.

A source can be enabled only if it is permitted to be enabled. Where the terms do not establish a right to redistribute, the connector refuses to fetch rather than leaving the decision to whoever clicks the toggle.

Sources and attribution

Named, so that anybody can check what each one publishes and on what terms, and so that no number here reads as ours when it is theirs. All three are switched off today.

  • ThreatFox, an abuse.ch project — indicators of compromise, including command-and-control and malware-distribution addresses. API documentation (opens in a new tab).
  • URLhaus, an abuse.ch project — URLs reported as distributing malware. API documentation (opens in a new tab).
  • Spamhaus — the spam-source layer. Their published terms cover reputation lookups rather than bulk data redistribution, so the connector ships switched off and declines to fetch until a data agreement exists that says otherwise. Usage terms (opens in a new tab).

This product includes GeoLite2 data created by MaxMind, available from maxmind.com (opens in a new tab). Country placement is only ever as good as that database, which is a free geolocation dataset and is approximate by design.

Questions

Questions people ask first

Why is the map empty?

Because no source is enabled, and we would rather show that than draw something. Two of the three can be switched on once the terms have been read and recorded; the third needs a data agreement we do not have. When the first one is enabled, indicators appear at the map heading above.

Does this show what your filters caught?

No, and it never will. This page shows other organizations' published observations. Customer mail, protected-domain traffic and the verdicts this gateway reached about real messages are kept entirely out of it.

Does a dark country mean the attackers are there?

No. It means machines reported by a source were placed there. The infrastructure is usually rented or compromised, and whoever is using it can be anywhere. A map of infrastructure is not a map of people.

Why do the category counts add up to more than the total?

Because one address can be in two categories at once — a controller and a payload host, for instance. Each category count is correct; the total counts each address once. They are not meant to sum.

Is an address on this map dangerous?

It was reported for something specific, usually a single path or file on a machine that may be shared with entirely legitimate services. Treat it as a report about that indicator, not as a verdict on the address or on whoever else is hosted at it.

Can I use the data?

The sources set those terms, not us, and they are named above with links so you can read them directly. We publish an aggregate view of what each source permits to be displayed, and nothing beyond it.

Following it

The beta application has the threat intelligence map as one of its options, and carries the mutual beta NDA. Applying is how you get told when a source is enabled rather than having to check a page for a map that is not there.

If what you actually need is what happens to your own mail, that is a different question with a real answer today: see features and attachment sandboxing.

Apply for the beta Check feature status