Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Punchbowl
14h ago
Aug 6th, 2026
Sublime Security
Credential phishing content and link (untrusted sender)
22h ago
Aug 6th, 2026
Sublime Security
Spam: Fake photo share
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
22h ago
Aug 6th, 2026
Sublime Security
Extortion / sextortion in attachment from untrusted sender
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
23h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Amazon
23h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing: Zero-width character obfuscation from freemail sender
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
AnonymousFox indicators
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Brand impersonation: Microsoft with embedded logo and credential theft language
3d ago
Aug 4th, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
3d ago
Aug 4th, 2026
Sublime Security