Enables the typosquatting detection feature so that the appliance can analyze suspicious sender and URL domains used in URLs within an email message body. The URL is compared against a blacklist of typosquatted domains to determine whether the URL is malicious. The URLs that match the blacklist of typosquatted domains are uploaded to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. Domain blacklists are updated when the system checks for new security content from the DTI Cloud.
After you have configured the appliance to detect typosquatting, you can view analysis of the results on the Alerts page in the Web UI.
The typosquatting detection feature is enabled by default.
Note
A one-way CONTENT_UPDATES license must be installed on the appliance for security content updates.
Syntax
[no] analysis url policy typosquatting enable
Parameters
noUse the no form of this command to disable typosquatting detection.
Example
The following example enables typosquatting detection on the appliance:
hostname (config) # analysis url policy typosquatting enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 8.0