CONBOOL
  • Blog
  • Dokumentation
  • Partner
  • Kontakt
Loslegen
CONBOOL

Sichere und automatisierte E-Mail-Sicherheit für Unternehmen – einfach, zentral und zuverlässig.

© Copyright 2026 Conbool. Alle Rechte vorbehalten.

Auszeichnungen
  • OMR Leader Badge für E-Mail-Sicherheit
Mitglied bei
  • Bitkom Mitglied – Digitalverband
  • BSI Allianz für Cyber-Sicherheit – Mitglied
Über uns
  • Blog
  • FAQ
  • Partner
  • Kontakt
Produkt
  • SecureMail
  • MailGuard
  • Disclaimer
  • Dokumentation
Add-ins
  • Disclaimer
  • SecureMail
  • SecureFiles
Rechtliches
  • Nutzungsbedingungen
  • Datenschutzerklärung
  • Impressum
Dokumentation
    • Funktionsübersicht
    • Richtlinien (Policies)
    • Link-Schutz
    • Black- & Whitelists
    • Benutzerfilter
    • Anhang- & MIME-Filter
    • Geo- & Netzwerk-Filter
    • Quarantäne
    • Spamschutz
    • DLP — Data Loss Prevention
    • System-Filter
    • Einstellungen
  • Rollen & Berechtigungen

Link Protection

All features of MailGuard Link Protection: URL analysis, QR code detection, click-time recheck, defanging, and tracking detection.

Link Protection

Link Protection is one of the most powerful modules in MailGuard. It analyzes all URLs in an email — including those in QR codes — and can defang, rewrite, or block them in real time.

Core Features

URL Analysis

Every link is checked in real time:

  • Redirect Following: URLs are resolved to their final destination. Configurable with a maximum hop count (default: 5).
  • Domain Reputation: The target domain is checked against reputation databases.
  • URL Shortener Detection: Shortened URLs (bit.ly, t.co, etc.) are flagged as potential obfuscation.
  • IP Host Detection: Links pointing to direct IP addresses (instead of domains) are flagged.
  • Display-Target Mismatch: Detects when the displayed link text contains a different URL than the actual link target (e.g., text shows paypal.com, link goes to evil-site.com).

Login Page Detection

MailGuard detects credential harvesting pages — fake login forms designed to steal credentials. These are automatically classified as suspicious.

Actions for Suspicious Links

ActionDescription
Increase ScoreSpam score is increased by the configured delta value
DefangingLinks are defanged (various modes available)
QuarantineEmail is moved to quarantine
BlockEmail is blocked

Defanging Modes

When defanging is selected as the action, three main modes are available:

ModeDescriptionExample
RewriteLinks are rewritten through a Conbool proxy (for click-time recheck)https://proxy.conbool.com/?url=...
RedactURL is replaced with custom text[Link removed - suspicious]
StyleLinks are defanged with configurable styles (see below)Combination of methods

Defanging Styles (Style Mode)

StyleDescriptionExample
hxxp Replacementhttp:// is replaced with hxxp://hxxp://example.com/link
Bracket EnclosureURL is enclosed in square brackets[http://example.com/link]
href RemovalThe clickable link is removed; the URL remains as textURL is no longer clickable

These styles can be combined. You can also configure different modes for suspicious and non-suspicious links.

Advanced Features

Click-Time Recheck

When enabled, links are not only checked upon receipt but also when clicked by the recipient. To do this, the URL is rewritten through a Conbool proxy:

  1. Email arrives → Link is checked and classified as safe.
  2. Link is rewritten with a Conbool proxy URL.
  3. Recipient clicks the link → Conbool re-checks the URL in real time.
  4. If the URL has become malicious between receipt and click, access is blocked.

This is particularly important because attackers often activate links only hours after sending a phishing campaign (known as "delayed phishing").

QR Code Detection

MailGuard extracts URLs from QR codes in email attachments and images:

SettingDescription
QR URL ExtractionURLs from QR codes are extracted and checked like regular links
QR DefangingQR codes with suspicious URLs are defanged (rendered unreadable)

QR code-based phishing ("quishing") is a growing threat, as QR codes are not detected by many traditional spam filters.

Tracking Parameters

MailGuard can detect and optionally remove tracking parameters in URLs:

SettingDescription
Tracking DetectionDetects known tracking parameters (utm_source, fbclid, etc.)
Tracking RemovalRemoves detected tracking parameters from URLs
Custom PatternsCustom regex patterns for tracking parameters

Unsubscribe Links

MailGuard respects unsubscribe links (List-Unsubscribe header) by default. These are not defanged or blocked in order to ensure email compliance.

Domain Rules

You can configure domain-based exceptions:

Rule TypeDescription
Allowed DomainsLinks to these domains are never defanged
Blocked DomainsLinks to these domains are always blocked

Each rule has a position for prioritization.

Configuration Example

A typical Link Protection configuration for a company:

  1. Link Protection: Enabled
  2. Action for suspicious links: Score +10
  3. Redirect Following: Enabled, max. 5 hops
  4. Domain Reputation: Enabled
  5. Login Page Detection: Enabled
  6. Click-Time Recheck: Enabled
  7. QR Code Extraction: Enabled
  8. QR Defanging: Enabled
  9. URL Shortener Detection: Enabled
  10. Allowed Domains: microsoft.com, google.com, own domains

Required Permissions

  • View: Owner, Operator, Analyst, Auditor
  • Configure: Owner, Operator

See Also

  • Policies – Apply Link Protection settings specifically through policies.
  • Feature Overview – Overview of all MailGuard modules.

Auf dieser Seite

  1. Link Protection
    1. Core Features
    2. Actions for Suspicious Links
    3. Advanced Features
    4. Domain Rules
    5. Configuration Example
    6. Required Permissions
    7. See Also