Configuring cousin domain profiles
Similar to impersonation profiles, cousin domain profiles help to mitigate domain impersonation risks. Similar to impersonation profiles that map display names, cousin domain profiles can map both inbound and outbound domain names to either be scanned or exempt from scanning. Domain names may be deliberately misspelled, either by character removal, substitution, and/or transposition, in order to make emails look as though they originate from trusted internal sources.
For example, if you configure a regular expression for the sender domain f?rtinet.com
, it will match f0rtinet.com
, but the legitimate and trusted sender domain fortinet.com
will also be detected as a cousin domain. To avoid this, you can add fortinet.com
into the exempt rules setting to avoid detecting it as spam.
To configure a cousin domain profile
-
Go to Profile > AntiSpam > Cousin Domain.
-
Either click New or Clone to add a profile, or double-click a profile to modify it.
Alternatively, see Batch editing antispam profiles.
-
Configure the following:
GUI item
Description
Select which protected domain this profile belongs to, or System (all protected domains can use this profile).
You can only see the domains that are permitted by your administrator profile. See About administrator account permissions and domains.
Enter a unique name for the profile.
Enter a comment or description.
-
In the Domain Pattern section, select From, To, or Exempt.
-
Click New and then configure the following:
GUI item
Description
Enter the domain name to be mapped to the email address. You can use wildcard or regular expression.
Select either:
- Wildcard
- Regular expression
- Look-alike
A look-alike pattern can be configured to specifically check for instances of recipient domain typos. For example, if a domain such as
fortinet.com
is configured with pattern type set to look-alike, any similar misspelled domains, such asfort1net.com
, are caught. See also Syntax.Since auto-detection is not applicable to outgoing policies, look-alike patterns are best suited for catching misspelled domains.
-
Repeat the previous step until you have entries that match all cousin domains.
-
Click Create or OK.
- To apply a cousin domain profile, select it in an antispam profile. For details, see Business email compromise section.