August 5th, 2026
INKY now recognizes mail relayed through Mesh and reads the original sending connection, so authentication and threat checks run against the real sender rather than Mesh's relay.
Select Mesh under Admin Center > Analysis > Upstream Provider, or leave the setting on auto-detect and INKY will identify it.
INKY recovers the sending IP, HELO, and MAIL FROM from the hop where Mesh accepted the message, and preserves any authentication results Mesh passed along.
Mesh is identified by its published inbound delivery ranges β including three EU ranges its own SPF record omits β so mail delivered from those ranges is recognized rather than silently missed.
Learn more about Upstream Provider for Inky here.
CyberHoot is now a selectable platform under Phishing Awareness Training, so its simulations and training assignments are handled without per-team exceptions.
Covers both CyberHoot mail streams: attack-based phishing tests from its dedicated relays, and training assignments that relay through Amazon SES.
Training assignments are matched on an authenticated cyberhoot.com sender rather than the shared SES addresses they arrive from, so no unrelated sender on that infrastructure inherits the same treatment.
This replaces the manual allow-list entries customers were adding by hand to stop quarterly training assignments being flagged on the brand names in their links.
Learn more about Phishing Awareness Training for Inky here.
Nimblr course invitations are now recognized as training mail, not just its simulations.
Previously only Nimblr simulations were identified, so course invitations were analyzed as ordinary mail.
Invitations are matched on Nimblr's authenticated sending domain plus its two published course-invitation addresses.
Simulations and invitations use the same sending domains, so both streams stay correctly and separately identified.
The Triage navigation item is now called Threat Center, and the browser page title matches it.
This is a rename only β the tabs and everything behind them are unchanged.
Tabs that are still rolling out carry an INTERNAL or BETA badge, which disappears on its own once the feature is generally available.

Learn more about Using the Threat Center Page for Inky here.
Message Deletions and Account Takeover used to open message detail as a slide-over panel. Every surface now opens the same centered modal with one responsive layout, so message detail looks and behaves identically wherever you open it from.
Message detail now describes what INKY found in plain terms instead of internal names.
INKY's assessment reads Neutral, Caution, or Danger in place of internal threat-level names.
A message's origin reads External or Internal.
Metadata rows were restyled, so labels and values are easier to scan.
The timeline now runs horizontally and includes remediation actions and allow-list and block-list updates, each attributed to whoever or whatever applied them, so a message's full history reads in one place.
The Delivered card expands to the complete recipient list and always shows its expand control, and a long delivery-hop list now scrolls inside its own card instead of stretching the view.
The Account Takeover enforcement view is easier to work through.
Redundant Dangerous Links and Phishing summary cards were removed.
The whole status box is clickable to end an enforcement, not just the shield icon.
Messages delivered while a user was under enforcement now show an ATO Delivered status, so you can tell them apart from mail delivered normally.
Threat Center enforcement rows and the Message Deletions list rendered backend timestamps as if they were already local, so times appeared shifted by your browser's offset from UTC. Both now display in your own timezone.
The quarantine timeframe selector offered "Last day", which read as a rolling 24 hours but actually selected the previous calendar day. It now reads Yesterday.
A long envelope sender on the Message Sent card now wraps inside the card instead of running past its edge.
The Ada chat launcher rendered with a white box behind it in dark mode. The launcher is now transparent against the dark background.