The system 1800 may provide message data to other integrations 1840, as well. For example, other integrations 1840 may include machine learning and/or natural language processing APIs. Furthermore, other integrations 1840 may also include querying a service for the latest known security threats. Combined, the other integrations 1840 may characterize a reported email as “good” or “bad”, i.e. determine with some probabilistic determination whether the reported email is generally malicious or non-malicious to aid an administrator in responding to threats. Alternatively, the characterization of a message as “good” or “bad” may cause the system to automatically perform some action on the message (e.g., quarantine), or otherwise automate the functions of the administrator.