Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Mimecast

ASecurity

Expert agent for Mimecast Email Security. Covers SEG, targeted threat protection, email continuity, DMARC analyzer, awareness training, and archiving/compliance. WHEN: \"Mimecast\", \"Mimecast SEG\", \"Mimecast URL protection\", \"Mimecast impersonation\", \"Mimecast continuity\", \"Mimecast DMARC\", \"Mimecast archive\", \"Mimecast awareness training\".

4 stars
0 votes
0 copies
1 views
Added 9/24/2026
securityrustgoshellgitapisecurity

Works with

cliapi

Security Analysis

A100/100

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill mimecast --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mimecast?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Mimecast
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-mimecast/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-mimecast)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: mimecast
description: "Expert agent for Mimecast Email Security. Covers SEG, targeted threat protection, email continuity, DMARC analyzer, awareness training, and archiving/compliance. WHEN: \"Mimecast\", \"Mimecast SEG\", \"Mimecast URL protection\", \"Mimecast impersonation\", \"Mimecast continuity\", \"Mimecast DMARC\", \"Mimecast archive\", \"Mimecast awareness training\"."
license: MIT
---

# Mimecast Email Security

This skill covers Mimecast's cloud-based email security platform covering the Secure Email Gateway, Targeted Threat Protection (TTP), Email Continuity, DMARC Analyzer, Security Awareness Training, and Mimecast Archive.

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Gateway configuration** — Policy rules, anti-spam/malware, content examination
   - **TTP (Targeted Threat Protection)** — URL protection, attachment protection, impersonation protection
   - **Email continuity** — Outage scenarios, emergency inbox, sync
   - **DMARC Analyzer** — DMARC deployment, report aggregation, enforcement journey
   - **Archive/compliance** — Retention policies, legal hold, eDiscovery
   - **Awareness training** — Phishing simulations, training campaigns

2. **Identify the Mimecast plan** — Gateway (core filtering), Mimecast Cloud Integrated (M365 API-based), Advanced Email Security, or the full suite with Archive.

3. **Recommend** — Provide guidance with Mimecast Administration Console (MAC) navigation paths, policy priority concepts, and PowerShell/API references where applicable.

## Gateway Architecture

### Mail Flow

Mimecast operates as an inline SEG with MX records pointing to Mimecast's infrastructure.

**MX records (varies by region):**
```
; US
example.com  MX  10  us-smtp-inbound-1.mimecast.com.
example.com  MX  20  us-smtp-inbound-2.mimecast.com.

; EU
example.com  MX  10  eu-smtp-inbound-1.mimecast.com.
```

**Mimecast data centers:** US, EU, UK, South Africa, Australia, Canada — customer selects region for data residency compliance.

**M365 direct injection:** Mimecast delivers to M365 using the tenant's direct MX (`tenant.mail.protection.outlook.com`) via a Smart Host connector. Lock M365 inbound connector to Mimecast IPs to prevent SEG bypass.

### Policy Framework

Mimecast policies are evaluated in priority order (1 = highest priority). Policies apply based on sender/recipient matching.

**Policy types:**
- **Anti-Spam and Virus** — Inbound scanning, scoring thresholds
- **Anti-Spoofing** — SPF/DKIM/DMARC enforcement + Mimecast's own DMARC check
- **Content Examination** — DLP rules, keyword scanning, attachment filtering
- **Attachment Management** — Extension blocking, sandboxing integration
- **URL Rewriting** — TTP URL protection configuration
- **Impersonation Protection** — Display name/domain lookalike detection

**Policy evaluation order:**
For each policy type, the first matching policy wins. Policies can be scoped to:
- All internal/external senders
- Specific sender domains
- Specific recipient addresses or groups
- Address groups and managed senders lists

### Anti-Spam and Anti-Malware

**Spam scoring:** Mimecast uses a 0-100 spam score. Configurable thresholds:
- **Spam** (typically 70+): Route to spam folder or quarantine
- **Graymail/Bulk** (50-70): Route to bulk folder or tag
- **Clean** (< threshold): Deliver normally

**Anti-malware engines:** Mimecast uses multiple AV engines (Sophos + Mimecast proprietary).

**Dangerous file types:** Pre-defined list of blocked extensions; customizable. Similar to Proofpoint's common attachments filter.

## Targeted Threat Protection (TTP)

TTP is Mimecast's advanced threat protection layer, covering URLs, attachments, and impersonation.

### TTP URL Protection

All URLs in inbound emails are rewritten to route through Mimecast's URL scanning service.

**Rewritten URL format:**
```
https://protect-{region}.mimecast.com/s/<encoded-url>?d=<domain>&c=<campaign>&p=...
```

**Time-of-click analysis:**
- URL reputation checked at click time
- Redirect chains followed
- Sandboxing of unknown/suspicious pages
- Block or allow based on verdict

**Policy settings:**
- **Scan level:** Aggressive / Relaxed — affects false positive rate
- **Inbound messages:** Enable for all inbound email from external senders
- **Internal messages:** Optional — catches compromised internal account links
- **Browser isolation:** Route suspicious URLs through isolated browser (add-on)

**User experience on block:** Mimecast presents a block page with the organization's branding. Can configure override option for users to report a false positive.

### TTP Attachment Protection

**Sandbox detonation:** Attachments are detonated in Mimecast's multi-layer sandbox.

**Supported formats:** Office documents, PDFs, archives, executables.

**Actions:**
- **Safe file (transcription):** Convert Office documents to a safe PDF/HTML version, deliver immediately. Prevents macro execution — balances security with zero delay.
- **Sandbox:** Hold while detonating; deliver clean or block malicious
- **Block:** Block all attachments of specified types

**Safe file delivery** is Mimecast's differentiator — the document is converted to a clean format and delivered immediately, with the original released after sandbox verdict. Similar in concept to MDO's Dynamic Delivery.

### TTP Impersonation Protection

Protects against display name spoofing and domain lookalike attacks.

**Detection methods:**
- Display name similarity matching (CEO/CFO names from directory)
- External sender using internal display names
- Domain lookalike analysis (similar to MDO impersonation detection)
- "New domain" detection (domains less than 30 days old)
- Internal domain impersonation (sending from outside but appearing internal)

**Configuration:**
1. Populate the list of protected names (executives, finance team)
2. Configure action: Tag subject, move to quarantine, block, or deliver with warning
3. Enable internal impersonation protection separately
4. Add trusted senders exceptions (PR agencies, vendors)

**Safety tips:** Similar to MDO — visual indicators shown to end users when impersonation is suspected.

## Email Continuity

Mimecast's Email Continuity service maintains email access during primary mail server outages.

### How Continuity Works

**Normal operation:**
```
Mimecast SEG → Deliver to M365/Exchange (direct)
                       ↓
              Messages spooled in Mimecast continuity store
              (rolling 30-day local copy maintained)
```

**During M365 outage:**
```
Inbound email → Mimecast SEG → Held in continuity queue
                               Users redirect to emergency inbox
                               
Outbound email → From emergency inbox via Mimecast
```

**Emergency inbox:**
- Accessible via Mimecast Personal Portal (web browser)
- Mimecast mobile app (iOS/Android)
- Mimecast Outlook plugin (Windows, Mac)
- Last 30 days of email available during outage

**Sync on recovery:**
When M365 comes back online:
1. Mimecast detects M365 availability (DNS + SMTP probe)
2. Held inbound messages delivered to M365
3. Messages sent via emergency inbox synced to Sent Items
4. Resolution confirmed by automated health checks

**RTO / RPO:**
- RPO: Near-zero for inbound email (spooled in Mimecast)
- RTO: < 5 minutes (emergency inbox available immediately during outage)

### Continuity for Compliance

Continuity spool is separate from Mimecast Archive. For compliance purposes, Mimecast Archive captures messages independently of the continuity spool.

## DMARC Analyzer

Mimecast DMARC Analyzer is a stand-alone or add-on product for DMARC deployment and management.

### Feature Set

**Aggregate report ingestion:** Automatically receives and parses RUA reports from all major mail providers (Google, Microsoft, Yahoo, Comcast, etc.).

**Dashboard views:**
- **Email streams:** All identified sending sources with authentication status
- **Compliant vs. non-compliant:** Volume breakdown, trend over time
- **Threat summary:** Unauthorized senders trying to use the domain
- **Top senders:** Largest volume sources, pass/fail rates

**Enforcement journey tracking:**
DMARC Analyzer guides organizations through the `p=none → quarantine → reject` journey:
1. Current policy and percentage shown on dashboard
2. Recommendations engine identifies remaining non-compliant senders
3. Step-by-step policy tightening with risk assessment
4. Automated alerts when new senders appear or pass rates drop

**Sender guidance:** For identified legitimate senders failing DMARC, Mimecast provides setup guides for common ESPs (HubSpot, Salesforce, Mailchimp, etc.).

**BIMI readiness check:** Shows whether DMARC policy is sufficient for BIMI (quarantine or reject) and provides BIMI setup guidance.

### Subdomain DMARC Management

Separate subdomains each need their own `_dmarc` records or inherit from the organizational domain. DMARC Analyzer shows subdomains identified in sending data and their authentication status.

**Subdomain policy (`sp=`):**
```
_dmarc.example.com TXT "v=DMARC1; p=reject; sp=quarantine; ..."
```
`sp=` applies to subdomains not covered by their own DMARC record.

## Mimecast Archive

Mimecast Archive provides cloud-based email archiving for compliance, legal hold, and eDiscovery.

### Architecture

**Capture:** All inbound, outbound, and internal email is captured at the Mimecast gateway (before delivery). Users cannot delete archived copies.

**Storage:** Encrypted at rest; immutable storage with tamper-evident audit trail.

**Retention:** Configurable retention policies (1 year, 7 years, indefinitely). Automatic deletion after retention period.

**Compression:** Mimecast uses single-instance storage — duplicate messages (same hash) stored once. Reduces storage footprint by 20-40%.

### eDiscovery and Legal Hold

**Legal hold:** Mark specified custodians under legal hold — messages preserved regardless of retention policy, cannot be expired.

**Search:**
- Keyword search (full-text search of message body and attachments)
- Sender/recipient/date range filters
- Subject line, attachment filename
- Tag-based filtering

**Export formats:** PST, EML, MSG, CSV with metadata.

**Audit trail:** All search and export actions logged with user identity, timestamp, search criteria.

### eDiscovery API

Mimecast Archive provides REST API for integration with legal discovery platforms (Relativity, Nuix, Everlaw):
```
POST /api/archive/get-message-list
Authorization: MC <encoded-credentials>
Body: {"data": [{"start": "2024-01-01", "end": "2024-01-31", "searchReason": "litigation-hold-001"}]}
```

## Security Awareness Training

Mimecast Security Awareness Training (acquired Ataata) provides adaptive training and phishing simulation.

### Key Features

**Adaptive training:** Machine-learning-based training engine adjusts training difficulty and frequency based on individual user risk scores.

**Phishing simulations:**
- Pre-built templates (thousands of templates mimicking real campaigns)
- Custom template creation
- Spear phishing simulations using LDAP user data
- Reporting on: click rate, credential submission rate, reporting rate

**Training content:** 2-4 minute microlearning videos. Topics: phishing, password hygiene, data handling, social engineering, remote work security.

**Risk scoring:** Per-user risk score based on:
- Phishing simulation failure rate
- Training completion
- Threat exposure (if integrated with TTP)

**CyberGraph integration:** Browser extension that provides real-time coaching when users interact with suspicious email links. Shows relationship graphs between sender and recipient.

## PowerShell and API

**Mimecast API authentication:**
```powershell
# Mimecast uses HMAC-SHA1 signed requests
# Application ID + Application Key from Administration Console
$AppId = "your-app-id"
$AppKey = "your-app-key"
$AccessKey = "your-access-key"
$SecretKey = "your-secret-key"

# Headers required:
# Authorization: MC {AccessKey}:{HMAC-SHA1 signature}
# x-mc-date: {RFC 2822 date}
# x-mc-app-id: {AppId}
```

**Common API endpoints:**
```
POST /api/message-finder/search        # Message trace/search
POST /api/archive/get-message-list     # Archive search
POST /api/ttp/url/get-logs             # URL click logs
POST /api/ttp/attachment/get-logs      # Attachment sandbox logs
POST /api/account/get-account          # Account information
POST /api/user/get-internal-users      # Directory listing
```

**Mimecast for Outlook (Outlook plugin):**
Provides users with: Archive search, spam management, large file send, email signature, and security awareness reporting button — all accessible from within Outlook.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →