This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to quarantine or block emails containing embedded URL?

Email Protection is enabled on Sophos UTM 9, however some emails are allowed through to Exchange server that have embedded URL's linking to malicious websites.  This type of email also has a modified header to make the sender appear to be a local domain user.  

Adding the Subject line to the Expression Filter helps some, but since the subject text is usually generic and random some legitimate emails are being quarantined.  Is there a better way to quarantine or block these type of emails?

Thank you.



This thread was automatically locked due to age.
Parents
  • Hi Tracy,

    same Problem here. I can filter some Mails with a expression filter that looked for "/rechnung" in the text.
    But we receive many Mails with a cryptic URL, so the expression filter doesn't work in these cases.

    Filtering for "http" and "https" would produce too much false positives...our users would need to add many senders into the whitelist, this would be unreasonable.

    Many greetings,

    Sebastian

Reply
  • Hi Tracy,

    same Problem here. I can filter some Mails with a expression filter that looked for "/rechnung" in the text.
    But we receive many Mails with a cryptic URL, so the expression filter doesn't work in these cases.

    Filtering for "http" and "https" would produce too much false positives...our users would need to add many senders into the whitelist, this would be unreasonable.

    Many greetings,

    Sebastian

Children
No Data