Enables the typosquatting detection feature so that the appliance can analyze suspicious sender and URL domains used in URLs within an email message body. The URL is compared against a blacklist of typosquatted domains to determine whether the URL is malicious. The URLs that match the blacklist of typosquatted domains are uploaded to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. Domain blacklists are updated when the system checks for new security content from the DTI Cloud.
After you have configured the appliance to detect typosquatting, you can view analysis of the results on the eAlerts > Alerts page.
The typosquatting detection feature is enabled by default.
Note
A one-way CONTENT_UPDATES license must be installed on the appliance for security content updates.
Syntax
[no] email-analysis policy typosquatting enable
Parameters
no
Disables typosquatting detection.
Example
The following example enables typosquatting detection on the appliance:
hostname (config) # email-analysis policy typosquatting enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 7.8. The
email-analysis policy typosquatting enablecommand was changed to theanalysis url policy typosquatting enablecommand in Release 8.0.