{
  "summary": "Captive-portal detection on the endpoint agent is dramatically faster - down from roughly 90-100 seconds to consistently under 20, confirmed against real hotel wifi. The agent now probes for a portal immediately after a network change instead of waiting on the ordinary heartbeat cadence, trusts a TLS certificate hostname mismatch as direct evidence of a portal, and exits bypass mode the instant connectivity is confirmed restored rather than leaving interception paused for up to another heartbeat interval. Fixed a bug where TLS interception - along with SMTP, mail-retrieval inspection, and ZTNA access routes, which share the same underlying ruleset - could silently stay disabled after a captive-portal bypass cycle even though the agent logged a normal configuration-complete message. Agent DNS resolution now falls back to public resolvers when the network-assigned one is unreliable, and enrollment retries start faster after a network change. The email-authenticity score behind a flagged inbound email is now persisted and shown in full in the admin UI, broken down signal by signal instead of just a total."
}
