Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing: 'Secure message' and engaging language
3d ago
Mar 27th, 2026
Sublime Security
Credential phishing: Financial lure via ActiveCampaign infrastructure
3d ago
Mar 27th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
3d ago
Mar 27th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
4d ago
Mar 26th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash (trusted reporters)
4d ago
Mar 26th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
4d ago
Mar 26th, 2026
Sublime Security
Callback phishing via Microsoft comment
4d ago
Mar 26th, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Mar 26th, 2026
Sublime Security
Lookalike sender domain (untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with urgent request (strict match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
VIP impersonation with BEC language (near match, untrusted sender)
5d ago
Mar 25th, 2026
Sublime Security
Brand impersonation: USPS
5d ago
Mar 25th, 2026
Sublime Security
Credential phishing: Fake card notification with tracking lure
6d ago
Mar 24th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
7d ago
Mar 23rd, 2026
Sublime Security
Credential phishing: Suspicious subject with urgent financial request and link
7d ago
Mar 23rd, 2026
Sublime Security
Spam: Fake dating profile notification
10d ago
Mar 20th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
10d ago
Mar 20th, 2026
Sublime Security
Brand Impersonation: Procore
10d ago
Mar 20th, 2026
Sublime Security
Link: Free file hosting with undisclosed recipients
11d ago
Mar 19th, 2026
Sublime Security
Service abuse: Substack credential theft with confusable characters and branded button redirects
11d ago
Mar 19th, 2026
Sublime Security