Notify Risk Similarity Level
Detect Differences in Email Address Character Count
Register Suspicious Similar Email Addresses
Manage Similar Email Addresses with Different TLDs Separately
Notify Risk Similarity Level
Notify Risk Similarity Level
Importance: Required / Reference to ITU-T X.1236 8.2.2 (1)
- Analyze the sender’s email address or domain of the received email and collect the cumulative email history of that sender to determine the Risk Similarity Level if the sender’s email address or domain is considered a similar domain. If a similarity is detected, alert the user and, if necessary, block the email.
- For example, if a user has received malicious emails from similar domains in the past, the system should detect similarities and warn the user or block the email accordingly.
- Risk Similarity Level Notification is a crucial feature in email security systems that informs users of potential risks when the sender’s email address or domain is identified as a similar domain.
- The Risk Similarity Level is determined based on algorithms and policies embedded in the email security system.
- The Risk Similarity Level is typically categorized as follows:
- Low: Similar domains are detected, but significant risks are not identified.
- Medium: Similarities in some emails are detected.
- High: High similarity is detected in the email.
- Once the Risk Similarity Level is determined, it should be communicated to the user. Users should be able to see that the received email has been categorized as a similar domain and check the Risk Similarity Level associated with that domain.
Detect Differences in Email Address Character Count
Detect Differences in Email Address Character Count
Importance: Required / Reference to ITU-T X.1236 8.2.2 (2)
- Apply criteria for detecting fraudulent similar email addresses based on the character count difference in email addresses.
- For example, if the character count difference compared to the genuine email address exceeds a specific threshold (usually within 1-3 characters), consider it as a suspicious similar domain and alert or block the email accordingly.
- This approach ensures sensitive detection of even minor character count differences, enabling more accurate detection of similar domains.
Register Suspicious Similar Email Addresses
Register Suspicious Similar Email Addresses
Importance: Recommended / Reference to ITU-T X.1236 8.2.2 (3)
- It is recommended to provide email security administrators with the capability to manually register suspicious similar email addresses.
- This allows administrators to promptly respond to new threats and monitor similar domains to protect users.
- The administrator registration feature offers flexibility to security teams, aiding in the rapid response and discovery of new attack patterns.
Manage Similar Email Addresses with Different TLDs Separately
Manage Similar Email Addresses with Different TLDs Separately
Importance: Recommended / Reference to ITU-T X.1236 8.2.2 (4)
- It is recommended to implement separate management for cases where email addresses are similar but have different top-level domains (TLDs).
- For instance, if the original TLD is “example.com” and an attacker uses the “example.net” domain to send emails, these two domains should be identified and monitored separately, with appropriate security measures applied.
- This approach allows users to distinguish between emails received from different domains and prevents attackers from bypassing email security by using similar domains.