Sublime news

Email bomb detection and prevention with Sublime

August 28, 2025

Email bomb detection and prevention with Sublime

Introducing next-gen email bomb protection from Sublime

Ready to see Sublime 
in action
Get a demo
Authors
Dr. Anna Bertiger
Dr. Anna Bertiger
ML Researcher
AJ Williams
AJ Williams
Product Manager

Email bombs are the DDoS of email – and they’ve proven difficult to stop over the years. In these attacks, a bad actor sends an avalanche of email to a mailbox to overwhelm, disrupt, evade security, or more. For example:

  1. Disable mailbox: An attacker can use an email bomb to disable a target mailbox or make it otherwise unusable due to the volume of messages.
  2. Machine takeover: An attacker can send an email bomb and then call the victim pretending to be the IT department looking into the attack. They’ll ask the user to install remote access tools so that the attacker can “fix” the user’s disrupted email. The attacker now has access to the victim’s computer.
  3. Account takeover: After successfully changing a user’s password to an external service, the attacker sends an email bomb at the same time as the password reset notification. The legitimate message about the password reset is then lost in the deluge, leaving the user unaware of the compromise.

The two aspects of these attacks that make them effective are: 1) the smokescreen emails are often legitimate mail that could be wanted in some contexts (if not during an attack), and 2) there are too many emails being sent at once for them to be addressed individually. To tackle email bombs, we wanted to take a new approach for detection and prevention.

Introducing email bomb protection from Sublime

Sublime’s new email bomb protection looks for sustained spikes in the number of emails received by a mailbox, opposed to looking at each message's contents independently. These spikes are required for an email bomb to be successful, but also evidence of the attack. Once a spike is identified, automations are triggered to move emails from the attack to the correct locations (spam goes to spam, attacks go to quarantine, etc.) for the duration of the attack.

Sublime’s approach to email bomb protection

When Sublime detects an email bomb, it quickly identifies, groups, and applies verdicts to the messages in the attack. This keeps unwanted and malicious email out of end user inboxes and cuts the noise for security teams trying to determine the intent of an attack.

It can sometimes take a while for the spike in emails to build, but there’s always a point where it becomes clear it’s a bomb. Once an email bomb has been identified:

  1. The mailbox is tracked as “part of an active bomb” so new messages are immediately processed by email bomb Automations.
  2. Sublime automatically reprocesses messages that arrived when the bomb started, and then runs those same email bomb Automations to auto-remediate the rest of the bomb.

So even if an email bomb is slow building and hard to detect initially, Sublime goes both forwards and backwards to clean it up.

To make this bidirectional processing possible with a high level of confidence, we use a combination of machine learning functionality. Attack Score, Natural Language Understanding (NLU), and Topic Modeling all help us cut through the noise. And because the messages have already been scoped as being an email bomb, we can be more aggressive with our verdicts.

Most importantly, all of our machine learning enrichments are available within Message Query Language (MQL), so you have the ability to leverage any of them directly within any custom email bomb automations you create beyond the ones we provide. We’ll show you how in the next section.

Using Sublime for email bomb remediation

Within the Remediate Threats section of the Sublime side panel, you’ll now see Email Bombs. Within the list view, you’ll see all the email bombs that have been detected, including those that are ongoing. You’ll also see the number of messages per bomb, as well as it’s detection and review statuses.

Opening a bomb gives you a histogram and stats on the bomb. In this view, you can easily see how many messages were automatically remediated, how many need human analysis, and which automation identified the email bomb. You can also click on any message to open its detail view to investigate further.

Automatically remediated messages in an email bomb

From here, you can quickly triage the messages that weren’t remediated automatically. These messages are most often legitimate emails that were received during the email bomb duration, but if any messages in the bomb slipped through, you can easily select one, multiple, or all of the messages and then choose the appropriate triage option.

Triaging messages in an email bomb

To see the logic behind the email bomb Automation that caught the attack, click on the Automation name at the bottom left corner. In this case, Remediate unwanted messages in an email bomb. Once open, you can explore the MQL logic, edit the Automation, reconfigure it, or delete it.

Go to Automations in your environment to see the full logic

Sublime stops email bombs

Email bombs are a nuisance that can be stopped. Start using email bomb remediation today or book a live demo to see how easy it can be to shut down this attack. For getting started and technical information, see our Email Bombs documentation.

Heading

About the authors

Dr. Anna Bertiger
Dr. Anna Bertiger
ML Researcher

Dr. Anna Bertiger is a Machine Learning Researcher at Sublime, where she uses math to find villains. Previously, she was a Principal Applied Scientist at Microsoft Security and a postdoctoral fellow in the Faculty of Mathematics at the University of Waterloo. Anna enjoys shutting down email threats with security expertise, advanced math, machine learning, and open collaboration.

AJ Williams
AJ Williams
Product Manager

AJ is a Product Manager at Sublime. Prior to Sublime, she operated as a founding member of the Enterprise team at Stripe, where she launched an incident detection and alerting infrastructure.

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

check
Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.

Related Articles

December 29, 2025
5 email security trends from 2025
Sublime news

5 email security trends from 2025

Brian BaskinPerson
Brian Baskin
Threat Research
Person
December 18, 2025
How to build fast similarity search for email from the ground up
Sublime news

How to build fast similarity search for email from the ground up

Ross WolfPerson
Ross Wolf
Engineering
Person
December 16, 2025
Evolving our brand as Sublime grows
Sublime news

Evolving our brand as Sublime grows

Omar JalalzadaPerson
Omar Jalalzada
Head of Design
Kirk JohnsonPerson
Kirk Johnson
Creative Director

Frequently asked questions

What is email security?
Email security refers to protective measures that prevent unauthorized access to email accounts and protect against threats like phishing, malware, and data breaches. Modern email security like Sublime use AI-powered technology to detect and block sophisticated attacks while providing visibility and control over your email environment.

Now is the time.

See how Sublime delivers autonomous protection by default, with control on demand.

BG Pattern