email-analysis policy typosquatting enable

Prev Next

Enables the typosquatting detection feature so that the appliance can analyze suspicious sender and URL domains used in URLs within an email message body. The URL is compared against a blacklist of typosquatted domains to determine whether the URL is malicious. The URLs that match the blacklist of typosquatted domains are uploaded to the Dynamic Threat Intelligence (DTI) Cloud for further analysis. Domain blacklists are updated when the system checks for new security content from the DTI Cloud.

After you have configured the appliance to detect typosquatting, you can view analysis of the results on the eAlerts > Alerts page.

The typosquatting detection feature is enabled by default.

Note

A one-way CONTENT_UPDATES license must be installed on the appliance for security content updates.

Syntax

[no] email-analysis policy typosquatting enable

Parameters

no

Disables typosquatting detection.

Example

The following example enables typosquatting detection on the appliance:

hostname (config) # email-analysis policy typosquatting enable

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.8. The email-analysis policy typosquatting enable command was changed to the analysis url policy typosquatting enable command in Release 8.0.