MailMum for Security / Abuse / SOC Teams
Investigating a suspicious sender usually means correlating logs from multiple systems and running network lookups by hand. MailMum does both of those automatically.
What you get during an investigation
- A permanent, queryable timeline of every DNS lookup MailMum answered: source IP, destination server, pass/block status, and timestamp.
- Automatic network/ownership information, fetched and cached for incoming IPs, so you have context on who operates a network without running a lookup yourself mid-investigation.
- One system, not several. Connection history and ownership context live together, instead of being spread across mail server logs, a separate lookup tool, and a spreadsheet.
- Per-server and per-account visibility, useful when an incident spans more than one mail server or more than one team.
Scope
MailMum works at the IP/connection layer only — it doesn’t inspect message content, so it complements content-scanning tools like SpamAssassin or Rspamd rather than replacing them. It’s also not (yet) a general-purpose SIEM: the audit trail is scoped to DNS-lookup events tied to mail servers, not a catch-all security event pipeline.
See the MailMum documentation for how mail servers are wired up to send traffic through MailMum in the first place.