Previewing malicious email URLs

Prev Next

Administrators and operators can click the URL Screenshot button in the Artifacts column on the Alerts page or in the URL region of the Alert Details page to preview information about email URLs that have been marked as malicious by FAUDE. The preview feature provides the following information about the malicious URL:

  • A screenshot of the URL

  • A response containing the target brand (the company being impersonated) information in JSON format

Advanced URL Defense must be enabled on the Email Security - Server appliance before you can use the URL preview feature. The Email Security - Server appliance retains the URL screenshot information for 7 days.

To preview information about malicious email URLs from the Alerts page:
  1. In the Web UI, click EAlerts and go to the Alerts page.

  2. In the list of alerts, locate the malicious URL you want to preview, and click the URL Screenshot button in the Artifacts column.

    A window displays a screenshot of the URL and a response containing the target brand information in JSON format.

  3. Click the X icon to close the dialog box and return to the Alerts page.

To preview information about malicious email URLs from the Alert Details page:
  1. In the Web UI, click EAlerts and navigate to the Alerts page.

  2. From the list of alerts, locate the malicious URL you want to preview, and double-click the alert to open the Alert Details page.

  3. In the URL region, click the URL Screenshot button.

    A dialog box appears, showing you a screenshot of the URL and a response containing the target brand information in JSON format.

  4. Review the information provided in the dialog box.

  5. Click the X icon to close the dialog box and return to the Alert Details page.