cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1797
Views
0
Helpful
1
Replies

Can a rule be written to look for hyperlinks and if the display is different from the destination insert a warning?

keithsauer507
Level 5
Level 5

In our paid penetration test our vendor recommended the following:

 

Create a filter that will inspect the message body of an email and compare a link's text to the URL in the link's HTML tag. If there is a difference, prepend a message to the message body warning the user to be cautious and include the real URL.

Additionally a filter can be created if an HTML formatted email does not have the RFC standard, alternate plain-text version of the message body.

 

 

Is this possible today with Cisco IronPort?  We have a call with proofpoint next Wednesday to intro their email security solution so if Cisco wants us to stay next year they better step up to the plate here.

1 Reply 1

Libin Varghese
Cisco Employee
Cisco Employee

We currently do not compare a URL with its text, however we utilize both for URL reputation and category lookups.

If there are specific scenarios or feedbacks you can open a TAC case or discuss with your Accounts team on upcoming roadmaps.

 

Regards,

Libin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: