HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Developer API
Docs
Developer API
Security & Threat Intelligence API

Security & Threat Intelligence API

Monitor automated anomaly alerts, inspect delivery volume spikes, and review security telemetry across user email aliases.

7 min read
Updated September 4, 2026

Monitor automated anomaly alerts, inspect abnormal delivery volume spikes, and review security telemetry across user email aliases.


Quick Reference

EndpointMethodRequired Scope / AuthDescription
/v1/security/suspicious-activityGETsecurity:readRetrieve active, unresolved suspicious traffic alerts for the account.
/v1/security/suspicious-activityPOSTInteractive Session (Bearer)Acknowledge and dismiss an active security alert.

Anomaly Detection & Threat Heuristics

AliasFleet continuously inspects incoming delivery envelopes to protect account reputation and detect credential abuse or spam targeting. The security engine evaluates traffic patterns against dynamic behavioral heuristics:

flowchart TD
    A["Inbound Delivery Stream"] --> B{"Burst Heuristics"}
    B -- "Normal Flow" --> C["Deliver to Forwarding Destination"]
    B -- "Spike > Baseline Threshold" --> D["Create Security Alert"]
    D --> E["Capture Forensic Envelope Samples"]
    E --> F["Notify Account & Flag in Security API"]
    F --> G{"Remediation Flow"}
    G -- "Interactive Session" --> H["POST /v1/security/suspicious-activity (Dismiss)"]
    G -- "Automation" --> I["Automated Quarantine via Rules Engine"]

Anomaly Triggers

  1. Volumetric Delivery Bursts: An alias receiving sudden, high-frequency inbound transmissions that significantly deviate from historical hourly baselines.
  2. Brute-Force Sender Probing: Repetitive message attempts from rotating subdomains, ephemeral origin servers, or recognized spam distribution networks.
  3. Repeated Denylist Collisions: Multiple consecutive delivery attempts from sender addresses or domains explicitly configured in your inbound firewall denylist.

List Active Security Alerts

GET /v1/security/suspicious-activity

Retrieves all active, unresolved security alerts generated for the authenticated user's aliases. Alerts remain active until explicitly dismissed.

Scope: security:readRate Limit: 60 req/minIdempotent: Yes

Query Parameters

This endpoint accepts no query parameters. It returns all unresolved alerts for the authenticated tenant ordered by lastAttemptAt descending.

Request Headers

HeaderTypeRequiredDescription
AuthorizationstringOptional*Bearer afp_...
x-api-keystringOptional*afp_... (*Provide either Authorization or x-api-key).
AcceptstringYesapplication/json

cURL Example

curl -X GET "https://api.aliasfleet.com/v1/security/suspicious-activity" \
  -H "Authorization: Bearer afp_live_9k3mF7qP2xL8vN5yR1wZ4tC6bJ0sD" \
  -H "Accept: application/json"

Response (200 OK)

{
  "alerts": [
    {
      "id": "alert_8a9b0c1d2e",
      "aliasId": "al_WTSGM57cIGy4oLUMoPQ2",
      "aliasEmail": "billing.alerts@mycompany.com",
      "attemptCount": 142,
      "sampleSenders": [
        "spammer@suspicious-relay.xyz",
        "crawler-bot@host-node-4.net"
      ],
      "sampleSubjects": [
        "Urgent invoice payment required",
        "Undelivered package notification"
      ],
      "firstAttemptAt": "2026-09-04T06:12:00.000Z",
      "lastAttemptAt": "2026-09-04T07:45:22.000Z",
      "alertSentAt": "2026-09-04T07:46:00.000Z"
    }
  ],
  "count": 1
}

Response Fields

FieldTypeDescription
alertsarrayList of active security alert objects.
alerts[].idstringUnique identifier for the security alert.
alerts[].aliasIdstringThe target alias identifier (al_...).
alerts[].aliasEmailstringFull email address of the affected alias.
alerts[].attemptCountintegerTotal number of delivery attempts detected during the incident window.
alerts[].sampleSendersstring[]Up to 5 sample sender email addresses identified during the anomaly.
alerts[].sampleSubjectsstring[]Up to 5 sample subject headers captured from incoming message envelopes.
alerts[].firstAttemptAtstringISO 8601 timestamp of the initial anomalous delivery attempt.
alerts[].lastAttemptAtstringISO 8601 timestamp of the most recent delivery attempt.
alerts[].alertSentAtstringISO 8601 timestamp when the security notification was dispatched.
countintegerTotal count of unresolved security alerts.

Error Responses

Status CodeCodeError MessageSolution
401UNAUTHORIZED"Unauthorized: Missing API Key or Session Token"Provide a valid API key or session token.
403INSUFFICIENT_SCOPES"Forbidden: Insufficient scopes"Ensure your API key includes security:read or security:write.
429RATE_LIMIT_EXCEEDED"Too Many Requests"Respect the 60 requests per minute rate limit.
500DATABASE_ERROR"Database query failed"Retry request with exponential backoff.

Dismiss Security Alert

POST /v1/security/suspicious-activity

Acknowledges and dismisses an active security alert, removing it from the active alert queue and recording human-in-the-loop resolution metadata.

Important

Interactive Session Required: To prevent automated scripts or compromised API keys from suppressing security notifications without human review, this endpoint strictly requires an interactive user session Bearer token. Standard developer API keys (afp_...) will receive an HTTP 403 SESSION_REQUIRED response.

Auth: Dashboard Session OnlyRate Limit: 60 req/minIdempotent: Yes

Request Headers

HeaderTypeRequiredDescription
AuthorizationstringYesBearer <SESSION_JWT_TOKEN> (Interactive dashboard session).
Content-TypestringYesapplication/json

Request Body Schema

FieldTypeRequiredConstraintsDescription
alertIdstringYesValid alert IDThe unique identifier of the alert to dismiss.
actionstringYesMust be "dismiss"The resolution action to execute.

cURL Example

curl -X POST "https://api.aliasfleet.com/v1/security/suspicious-activity" \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \
  -H "Content-Type: application/json" \
  -d '{
    "alertId": "alert_8a9b0c1d2e",
    "action": "dismiss"
  }'

Response (200 OK)

{
  "success": true,
  "message": "Alert dismissed"
}

Error Responses

Status CodeCodeError MessageReason
400BAD_REQUEST"alertId required"Missing alertId parameter in the request payload.
400BAD_REQUEST"Invalid action"The action field must be "dismiss".
403SESSION_REQUIRED"Forbidden: This endpoint is restricted to interactive dashboard sessions and cannot be accessed using an API key."Attempted dismissal with an API key (afp_...) instead of an interactive session token.
429RATE_LIMIT_EXCEEDED"Too Many Requests"Client exceeded the 60 requests per minute limit.

Threat Remediation Best Practices

When an alert indicates anomalous delivery activity on an alias, consider the following defense-in-depth remediation steps:

1. Inbound Firewall Rules

If the alert identifies persistent bad actor domains in sampleSenders, add an envelope denylist rule via the Sender Rules API:

curl -X POST "https://api.aliasfleet.com/v1/sender-rules/blacklist" \
  -H "Authorization: Bearer afp_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "sender": "*@suspicious-relay.xyz",
    "note": "Blocked following volumetric burst alert alert_8a9b0c1d2e"
  }'

2. Automated Quarantine via Rules Engine

Configure conditional rules in the Rules Engine API to inspect high-risk indicators (such as spam_score > 5.0 or missing SPF/DKIM verification) and route them to quarantine or silent drop:

{
  "name": "Quarantine High Spam Inbound",
  "priority": 10,
  "match_type": "ANY",
  "conditions": [
    {
      "field": "spam_score",
      "operator": "greater_than",
      "value": "5.0"
    }
  ],
  "actions": [
    {
      "type": "quarantine"
    }
  ],
  "stop_processing": true
}

3. Alias Deactivation or Rotation

If an alias has been exposed in a public leak or credential stuffing campaign, disable inbound forwarding immediately by moving it to the trash via the Aliases API:

curl -X POST "https://api.aliasfleet.com/v1/aliases/al_WTSGM57cIGy4oLUMoPQ2/trash" \
  -H "Authorization: Bearer afp_live_..."

Frequently Asked Questions

What triggers an automated suspicious activity alert?

Alerts are automatically triggered when an alias experiences an anomalous delivery surge exceeding baseline volume, repeated delivery attempts from blocked or invalid senders, or rapid SMTP envelope retries within a compressed time window.

Why does dismissing an alert require interactive session authentication?

To prevent compromised API keys or rogue automation scripts from clearing critical incident flags without human oversight, alert dismissal strictly requires an authenticated dashboard session, returning HTTP 403 SESSION_REQUIRED if an API key is used.

Can I query security alerts programmatically using an API key?

Yes. Querying active alerts via GET /v1/security/suspicious-activity requires the security:read scope and is fully compatible with developer API keys and CI/CD security monitors.

What forensic telemetry is provided in each alert payload?

Each security alert includes the target alias ID, alias email address, total attempt count, arrays of sample sender addresses and message subjects, first and last attempt timestamps, and the original alert notification timestamp.

Was this article helpful?

Related articles

Identity & Token Introspection API

Verify token validity, inspect active permission scopes, and retrieve account metadata using the Identity API.

Aliases API

Create, list, inspect, update, and soft-delete email aliases programmatically using the AliasFleet REST API.

Alias Destinations & Batch Operations API

Configure multi-destination forwarding fanout, execute atomic batch updates across up to 100 aliases, and fine-tune per-alias privacy settings.

Domains API

Query shared platform domains, register custom brand domains, verify DNS records, and inspect catch-all forwarding rules.

Destinations API

Register destination inboxes, execute 6-digit OTP verification challenges, configure per-channel sender identities, and manage routing fallbacks.

Content

Quick ReferenceAnomaly Detection & Threat HeuristicsAnomaly TriggersList Active Security AlertsQuery ParametersRequest HeaderscURL ExampleResponse (`200 OK`)Response FieldsError ResponsesDismiss Security AlertRequest HeadersRequest Body SchemacURL ExampleResponse (`200 OK`)Error ResponsesThreat Remediation Best Practices1. Inbound Firewall Rules2. Automated Quarantine via Rules Engine3. Alias Deactivation or Rotation

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket