MailMum for Security / Abuse / SOC Teams

Investigating a suspicious sender usually means correlating logs from multiple systems and running network lookups by hand. MailMum does both of those automatically.

What you get during an investigation

Scope

MailMum works at the IP/connection layer only — it doesn’t inspect message content, so it complements content-scanning tools like SpamAssassin or Rspamd rather than replacing them. It’s also not (yet) a general-purpose SIEM: the audit trail is scoped to DNS-lookup events tied to mail servers, not a catch-all security event pipeline.

See the MailMum documentation for how mail servers are wired up to send traffic through MailMum in the first place.