Suricata : How to detect IMAP data

Hi,
Anyone has any idea if there is anyway for suricata to detect IMAP data? Does suricata support alert “imap” or is there a way for us to capture the imap related packets?

alert imap any any <> any any (content: “Begin compression”; nocase; sid: 1000001; rev: 1; msg: “Keyword compression found”:wink:

i saw some similar question posted via the following links but would like to check if there is any further updates on this?

Many thanks in advance

I developed it myself

alert imap is supported
https://suricata.readthedocs.io/en/suricata-6.0.3/rules/intro.html?highlight=IMAP#protocol