email-analysis policy url-overlay enable

Prev Next

Enables or disables the URL overlay detection feature to allow the Email Security — Server appliance to identify suspicious mismatches between the URLs that are embedded in an email message.

URL overlay is a technique that hides a URL that points to a phishing site under a different, visible URL. When users click the visible link, they might be lead to a website that contains malware. The URL is compared with a list of URL overlay characteristics. The URLs that match the characteristics of domain mismatches, URL text string mismatches, or protocol mismatches are submitted for URL Dynamic Analysis. If dynamic analysis determines the URL is malicious, the results of the analysis are displayed on the eAlerts > Alerts page in the Web UI. For details about URL Overlay Detection, refer to the "Monitoring Alerts" chapter of the Email Security — Server User Guide.

Note

The URL overlay detection feature is enabled by default.

Syntax

[no] email-analysis policy url-overlay enable

Parameters

no

Disables URL overlay detection.

Examples

The following example enables URL overlay detection on the appliance:

hostname (config) # email-analysis policy url-overlay enable

The following example disables URL overlay detection on the appliance:

hostname (config) # no email-analysis policy url-overlay enable

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.0