Security and logs
This area helps administrators discover and investigate events. Counts, alerts, and security signals are evidence to assess, not proof on their own that an attack or incident has occurred.
Email security and alerts
Email security and Meilhygiene collect status for domains, email protection, and alerts. Start with items marked critical or needing review, but always assess the context:
- Open the alert or domain and read what was actually observed.
- Check whether a planned change, new provider, or new software can explain it.
- Investigate affected users or domains with the audit log and mail flow when necessary.
- Document the conclusion and follow the organization’s incident procedure if something appears suspicious.
Audit log
Activity and logs shows workspace events including time, action, actor, IP address, and device when available. Use filters for service, category, person, action, and time period. You can also export the filtered result as CSV.
The audit log is for traceability and follow-up. It is not a remote-control function and does not alter historical events. Limit access to log data because it can contain personal and security-relevant information.
Search mail flow
Mail search is used to investigate delivery and status in the organization’s mail flow. You can narrow by sender or recipient, subject, direction, IP address, and time period, then view delivery status and a timeline.
This is not a general full-text search of employee mailboxes. Use it only when you have a legitimate operational or security need, and follow your organization’s privacy and access procedures.
GDPR data export
Data export is available to workspaces where the function is enabled. A request can include email, files, calendar, and contacts for one selected user. Select only data necessary for the specific request and follow the status in Admin before expecting a download.
Data export is a sensitive offboarding and privacy tool. Verify the identity and authority of the person requesting the export, store the result securely, and do not download it to a shared computer.
DNS / Web protection
DNS / Web protection is part of meil Business and is used only in business workspaces. It can protect office networks against known malware, phishing, botnet, and cryptomining domains. Administrators activate and manage it for the workspace. See the detailed DNS guide for resolvers, office IPs, policy, exceptions, overview, and limitations.
When the service is active, administrators can:
- add the office’s public IP addresses as protected network points
- use the resolver addresses shown in Admin on a router or client
- choose filtering policies, for example phishing or SafeSearch
- create allowed and blocked domain exceptions
- view queries, blocks, and security insights
A blocked query can result from a legitimate requirement, a configuration error, or a threat. Before creating an exception, verify the domain, affected service, and why the filter intervened. Large or permanent exceptions reduce protection.
When should you escalate?
Investigate quickly when you see several independent signals, such as failed sign-ins, new traffic to unexpected infrastructure, high block rates, or changes without a known administrator. Keep the time and relevant event IDs, and contact support through Admin without sharing passwords, keys, or complete data exports.