Detection Method: Sender analysis

Sender analysis helps you assess whether an email is coming from a legitimate sender. By combining machine learning and rules-based logic, this method evaluates sender profiles, looking at things like authentication results, past behavior, and patterns from previous messages.
Sender analysis can help you detect:
  • Impersonation attempts using fake email addresses or domains
  • Suspicious senders with authentication issues (e.g., SPF, DKIM, DMARC failures)
  • Unusual behavior based on historical patterns, like frequent urgent requests
  • Senders linked to known phishing or malware campaigns
  • Changes in sender behavior that could indicate a compromised account
For example, an attacker might try to impersonate a trusted vendor or executive. The email address or domain might look real, but sender analysis can catch issues like failed authentication checks or past suspicious activity, helping you spot these threats before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: FedEx
2d ago
May 8th, 2026
Sublime Security
Attachment: SVG files with evasion elements
2d ago
May 8th, 2026
Sublime Security
Brand impersonation: Quickbooks
2d ago
May 8th, 2026
Sublime Security
Service abuse: Microsoft with suspicious indicators in subject
3d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
3d ago
May 7th, 2026
Sublime Security
Brand Impersonation: PayPal
3d ago
May 7th, 2026
Sublime Security
Spam: Website errors solicitation
3d ago
May 7th, 2026
Sublime Security
Business Email Compromise (BEC) with request for mobile number
3d ago
May 7th, 2026
Sublime Security
Brand impersonation: Booking.com
4d ago
May 6th, 2026
Sublime Security
Suspicious newly registered reply-to domain with engaging financial or urgent language
4d ago
May 6th, 2026
Sublime Security
Link: Cloud service with credential theft language
4d ago
May 6th, 2026
Sublime Security
Callback phishing via calendar invite
4d ago
May 6th, 2026
Sublime Security
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
4d ago
May 6th, 2026
Sublime Security
Service abuse: Zoom with newly registered reply-to domain
6d ago
May 4th, 2026
Sublime Security
PayPal invoice abuse
6d ago
May 4th, 2026
Sublime Security
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
6d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
6d ago
May 4th, 2026
Sublime Security
BEC/Fraud: Student loan callback phishing
6d ago
May 4th, 2026
Sublime Security
Canva infrastructure abuse
6d ago
May 4th, 2026
Sublime Security