Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

URL Protection

Hello,

at the moment it is only possible to allow curtain domains for the url protection. That´s nice for things like sharepoint and so on.

But one thing that we think is realy missing at the moment is, that there is no block list for the url protection.

As example we often recieve mails with url's ending with r2.dev, wich are definitly bad url's in that cases.

So at the moment we can't block them in the sophos email protection. The only way is to let´s say check every day the sophos

email protection reports und then report the mentionend mails as spam for further analyses to sophos.

This is not the solution.

Best regards



Added TAGs
[edited by: Raphael Alganes at 3:55 PM (GMT -8) on 26 Nov 2024]
Parents Reply
  • I tried it again. It's not working. I have set that regular expression:

    I have send a mail with embedded links: web.tld (Tld as shown in picture above | Yesterday my account has been blocked beacause i posted the in the picture above mentionend tld | what i can't understand | In the meantime it's unblocked again) and https://web.de. But the mail is accepted and delivered successfull. I have send a mail before that mail with the embedded link: netphone.test.proton.extra.mime.tld. Here sophos email protection matched the regex and put it in the qurantine. And so it goes on. Thats a problem. We see many spam attemps like descriped in the beginning. But there is at the moment no solution from sophos wich helps us dealing with that. An as already described the solution from the support team send the mails for analyses no solution for that. Next thing is that the regex is limited to 50 characters.

Children