Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Adobe legitimate domain with document approval language
15h ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-adobe-legitimate-domain-with-document-approval-language-237f4da4
Extortion / sextortion (untrusted sender)
20h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Fake voicemail notification (untrusted sender)
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/fake-voicemail-notification-untrusted-sender-74ba7787
Service abuse: Microsoft Power BI callback scam
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e
Brand impersonation: Dropbox
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-dropbox-61f11d12
Callback phishing via calendar invite
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-calendar-invite-95c84360
Callback phishing in body or attachment (untrusted sender)
1d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Brand impersonation: AuthentiSign
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b
Brand impersonation: Blockchain[.]com
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-blockchaincom-0d85e555
Link: Self-sent message with quarterly document review request
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/link-self-sent-message-with-quarterly-document-review-request-3c42cec6
Job scam with specific salary pattern
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/job-scam-with-specific-salary-pattern-af7f9e21
Brand impersonation: Fake Fax
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: USPS
3d ago
Jan 20th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Impersonation: Internal corporate services
3d ago
Jan 20th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-internal-corporate-services-3cd04f33
Brand impersonation: Xodo Sign
7d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-xodo-sign-e6139052
Service abuse: GetAccept callback scam content
7d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b
BEC: Employee impersonation with subject manipulation
7d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/bec-employee-impersonation-with-subject-manipulation-9adfc77b
Brand impersonation: Quickbooks
8d ago
Jan 15th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1
Spam: Commonly observed formatting of unauthorized free giveaways
9d ago
Jan 14th, 2026
Sublime Security
/feeds/core/detection-rules/spam-commonly-observed-formatting-of-unauthorized-free-giveaways-8bc49fa3
Brand impersonation: SendGrid
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f