QR Code scanning

Updated 2 days ago by admin

The Email Security product has the ability to scan QR Codes when processing email in addition to on-demand scanning of URLs from email using the LinkScan service. This helps to prevent QR code phishing or "quishing" attacks.

Quishing involves tricking someone into scanning a fake QR code with their phone or device. The QR code then takes the user to a fraudulent website that might download malware or ask for sensitive information.

The Email Security product provides a QR Code Detection condition for Message Rules which when activated will attempt to detect QR codes in:

  • Images attached to emails
  • Images linked within the email content
  • Embedded binary files

To enable QR code scanning, follow these steps:

  1. Navigate to Products -> Email Security -> Message Rules
  2. Create a new rule
  3. Drag the Direction condition into the Selected Conditions column and set its value to Inbound
  4. Drag the Detect QR Code condition into the Selected Conditions column and set its value to one of the following:

Option Value

Description

Detect

The Detect QR Code condition will trigger if a URL is detected in the QR code, regardless of its type or reputation.

Detect & Classify

QR Code URLs will be extracted and passed to the URL Scanner condition and if classified as a threat the Detect QR Code condition will trigger. This relies on threat intelligence being aware of the malicious URL.

  1. Select your preferred Action such as Notify Recipient and drag it to the Selected Actions column
  2. Select your preferred Final Action such as Quarantine and drag it to the Final Action column

Your rule may look like this:

  1. Drag your new rule to a suitable position in your Message Rules list so that it runs prior to message delivery
  2. You can use the Analytics -> Email Activity report to highlight messages that have triggered this rule


How did we do?