Review domains in sent email with DNSFilter
Keep a security review of domains you have emailed about attached to the sent-message context.
Trigger
Email Sent
Triggers when a Gmail message is sent by the authenticated user. It polls the 'SENT' label and emits metadata including sender, recipients, subject, timestamp, and thread ID.
Action
Suggest Domain Threat
Tool to suggest a fqdn as a potential threat. use after identifying a suspicious domain to verify its threat categorization.
Why this helps
After sending a security-related email, it is easy to lose track of whether its domains still need review.
- Review domains included in sent messages without reopening each thread.
- See DNSFilter threat suggestions in a run report.
- Keep the sent message subject and thread context with the review.
Setup
Build it in a few focused steps.
- 1Connect Gmail and DNSFilter once in the Notis portal.
- 2Create an automation in Automations, New Automation, and give it a clear name.
- 3Tell Notis to extract domains from each sent message, request DNSFilter threat suggestions, and summarize the message context with the results.
- 4Pick the Email Sent trigger and choose where run reports should go.
- 5Test with one real sent message containing a domain.
Questions about this workflow
Does the workflow check every message in the thread?
The trigger provides metadata for the sent message. Ask Notis to use only content available from that message and report if more context is needed.
Will DNSFilter block a domain based on the suggestion?
No. The action suggests a threat classification and does not change a block list or policy.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Gmail to Dnsfilter. A trigger fires from one place; an action lands in another.
Gmail triggers
Dnsfilter actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Create IP Address
Tool to create a new ip address in dnsfilter. use after confirming the target network id exists.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Application Category
Tool to get basic information of a specific application category. use when you need details for a given application category id.
Email Sent
Triggers when a Gmail message is sent by the authenticated user. It polls the 'SENT' label and emits metadata including sender, recipients, subject, timestamp, and thread ID.
Get Billing Information
Tool to retrieve basic billing information for an organization. use when you need to obtain billing details for reporting or automation tasks.
New Gmail Message Received Trigger
Triggers when a new message is received in Gmail.
Get Category
Tool to get basic information of a specific category. use when you need to retrieve details for a category by its id.
Get IP Address
Tool to get basic information of the specified ip address. use when you need to fetch metadata for a particular ip after authentication.
List All Categories
Tool to list all categories including internal categories. use when you need the complete set of filtering categories.
List All IP Addresses
Tool to list all user-associated ip addresses. use when you need a comprehensive list of all ip address entries in your organization.
List All MAC Addresses
Tool to list all mac addresses with basic information. use when you need to retrieve all mac address entries in your organization.
Connect any two apps with Notis in the middle.
Gmail and Dnsfilter, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Dnsfilter.