Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Suspicious message with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Brand impersonation: Social Security Administration
6h ago
Sep 16th, 2026
Sublime Security
Brand impersonation: Wix
1d ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
2d ago
Sep 14th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Brand impersonation: Netflix
5d ago
Sep 11th, 2026
min0k
Spam: Fake photo share
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
5d ago
Sep 11th, 2026
Sublime Security
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
5d ago
Sep 11th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
5d ago
Sep 11th, 2026
Sublime Security
Link: Suspicious TLD hosting client.js with cf beacon
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: USPS
6d ago
Sep 10th, 2026
Sublime Security
Brand impersonation: Microsoft
6d ago
Sep 10th, 2026
@amitchell516
Business Email Compromise: Request for mobile number via reply thread hijacking
6d ago
Sep 10th, 2026
Sublime Security
Attachment: ICS calendar invite with photo/file share lure
7d ago
Sep 9th, 2026
Sublime Security