About typosquatting

Prev Next

The typosquatting detection feature allows you to identify suspicious sender and URL domains in URLs that are embedded in an email message.

Typosquatting is a form of cybersquatting (also referred as domain squatting) that relies on mistakes such as typographical errors to bring you to a malicious website. Typosquatting is a technique that tricks you to access a phishing site. Typosquatters register misspellings or alternate spellings of legitimate domains (for example, trellix.com). When users accidentally mistype a URL, (for example, "trellix.com" may be presented as "tRellix.com"), they might be lead to a website that contains malware.

The Email Security - Server appliance analyzes suspicious sender and URL domains used in URLs within an email message body. The URL is compared against a blacklist of typosquatted domains to determine whether the URL is malicious. The URLs that match the blacklist of typosquatted domains are uploaded to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. If the URL is detected as a typosquatted domain, the URL is marked as malicious and the appliance immediately blocks the email from being delivered to you and marks the malicious email for quarantine. Domain blacklists are updated when the system checks for new security content from the DTI Cloud.

Note

Typosquatting is enabled by default.

Task list for managing typosquatting

Complete the steps for managing typosquatting in the following order:

  1. Log in to the CLI.

  2. Validate DTI access on the appliance by using the show fenet status command. For details about how to validate DTI access, refer to the System Administration Guide.

  3. Download and install the latest security content with new domain blacklists by using the fenet security-content apply-update command. For details about how to update security content, refer to the System Administration Guide.

  4. Verify that the appliance is enabled to detect typosquatting. Use the show analysis url-policy command.

    Note

    In Release 8.0, do not use the show email-analysis policy command to verify the status for typosquatting detection.

  5. View typosquatting alerts in the Web UI. For details about how to view typosquatting alerts in the Web UI, see Viewing the malicious domain details grouped by alert using the Web UI.