Your UniFi Said "Threat Detected and Blocked." Now What?
If you run a UniFi gateway, you have probably gotten the UniFi OS email. Subject line: Threat Detected and Blocked. Dark card. A public IP. A private IP. A signature name that looks like alphabet soup.
The first time a UniFi IDS/IPS alert shows up, it feels like a breach. Most of the time it is the opposite. Intrusion detection and prevention on the Ubiquiti edge saw a bad connection, dropped it, and emailed you that it did.
What a UniFi Threat Detected and Blocked email actually is
UniFi intrusion detection (IDS) and intrusion prevention (IPS) watch traffic at the edge of your business network. A lot of the UniFi OS alerts we see for San Diego businesses are “poor reputation IP” or CINS-style lists. A scanner on the internet knocked on the door. Your UniFi firewall did not open it.
Typical tells it is noise:
- Verdict is Blocked. The packet never became a session. That is IPS doing the job.
- Risk is Low or Medium. High exists. It is less common on a healthy UniFi site.
- A few dozen bytes, one or two packets. That is a probe, not a download.
- Source is a cloud IP on port 443 talking inbound to a workstation, server, or UniFi Protect camera. The internet is noisy. This is normal for a public-facing San Diego office.
That is still worth logging in your network security monitoring. It is not worth cancelling your afternoon.
When a UniFi IDS/IPS alert is not noise
Call your managed service provider, or Key MSP, if any of this is true:
- The verdict is Detected and not blocked, or the same host keeps lighting up after UniFi already blocked it.
- The destination is a server that holds client files, Microsoft 365, email, or line-of-business apps, and the signature is an exploit, not a reputation list.
- You also have a user report: slow network, a pop-up, a ransom note, or a login you do not recognize.
- The alert names ransomware, a botnet, or a known exploit kit, and it is talking to more than one internal address.
Then a San Diego MSP should pull the UniFi client, check that host, and decide if it is isolate-and-scan or just a tighter firewall rule.
What you should not do
Do not click every “learn more” link in a panic. Do not forward the raw UniFi OS email to the whole office. Do not shut the UniFi gateway off. And do not assume a blocked threat means someone is already inside.
Also: these notifications.ui.com emails often go to a shared UniFi mailbox so Ubiquiti login and 2FA codes still work. That is fine. Threat and intrusion mail should be read by whoever owns cybersecurity, not by everyone on the thread.
How Key MSP handles UniFi threat monitoring
Key MSP is a Ubiquiti Certified Partner. For the San Diego businesses we manage, UniFi Threat Detected and Blocked mail does not sit in an owner’s inbox hoping someone notices. We read the signature, the verdict, and the host. Blocked reputation noise gets filed. A real intrusion attempt gets a ticket and a check of that device.
If you already have UniFi Protect, UniFi Access, or a UniFi gateway and you are the one opening those emails, that is a reasonable time to ask whether managed IT and managed cybersecurity should sit with a local team that does this all day.
The goal is not more alerts. It is knowing which UniFi IDS/IPS events matter.
Related articles
AI Safety for SMBs: Before Your Team Hands Company Data to LLMs
AI tools are moving into everyday business workflows faster than most companies can evaluate them. Here's how to govern AI use before sensitive data is exposed.
Read article
Holiday Tech Travel Tips: Staying Connected and Secure on the Go
Holiday travel opens the door to cyber risks. Here are nine practical tips for keeping your devices, accounts, and data secure while traveling.
Read article
Protecting Your Business from the Microsoft Excel Remote Code Execution Vulnerability
A patched Microsoft Excel vulnerability allowed attackers to execute code remotely by sending a malicious Excel file. Here's how to protect your business and stay safe.
Read article