INTEGRITY Cloudflare Docs

How Email security detects phish

Email security uses a variety of factors to determine whether a given email message, a web domain or URL, or specific network traffic is part of a phishing campaign (marked with a Malicious disposition) or other common campaigns (for example, Spam).

These small pattern assessments are dynamic in nature and — in many cases — no single one in and of itself will determine the final verdict. Instead, our automated systems use a combination of factors and non-factors to clearly distinguish between a valid phishing campaign and benign traffic.

Scope

Email Security inspects email protocols such as SMTP, IMAP, and POP3 to detect phishing, business email compromise (BEC), spoofing, and malware delivered via email.

For protection against DDoS attacks targeting web and network infrastructure at layers 3, 4, and 7 — including TCP, UDP, DNS, and HTTP/S traffic — refer to DDoS Protection.

Sample attack types and detections

Malicious payload attached to the message

Encrypted malicious payload attached to the message, with password in message body as text

Encrypted malicious payload attached to the message, with password in message body as an image

Malicious payload within an archive attached to the message

Malicious URLs within message body

Malicious payload linked through a URL in a message

Blind URL campaigns

Malicious URLs within a benign attachment in the message

Malicious URLs within an archive attached to the message

Malicious URLs behind URL shortening services

Malicious URLs associated with QR codes (QR Code Phishing Attacks, Quishing)

Instant crawl of URLs within message body

Credential Harvesters

Domain Spoof Attacks

Domain proximity attacks

Email Auth violations

Name Spoof Attacks / Executive Attacks (BEC)

Fileless / Linkless campaigns (BEC)

Deferred campaign attacks

IP-based spam

Content-based spam

Web phishing

Mobile phishing

Network phishing