Viewing the malicious domain details grouped by alert using the Web UI

Prev Next

The eAlerts > Alerts page of an Email Security - Server appliance lists the details, grouped by alert, of email that is blocked because it contains domains that match known sender and URL domain blacklist entries. After you have configured the Email Security - Server appliance to detect typosquatting using the CLI, you can view analysis of the results on this page.

Prerequisites

  • Administrator, Monitor, or Analyst access to the Email Security - Server appliance

  • A one-way CONTENT_UPDATES license for security content updates

  • Download and install the latest security content with new typosquatted domains by using the fenet security-content apply-update command. For details about how to update security content, refer to the Email Security — Server System Administration Guide.

  • Verify that the appliance is enabled to detect typosquatting. Use the show analysis url-policy command.

    Note

    In Release 8.0, do not use the show email-analysis policy command to verify the status for typosquatting detection.

To view the malicious domain details grouped by alert:
  1. In the Web UI, click the eAlerts tab.

  2. Click Alerts.

  3. To expand the row to show detailed results, click the ID name in the ID column or the type name in the File Type column.