Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

How Account Takeover Protection Works

Prev Next

Overview

Trustifi's Account Takeover Protection acts as a third layer of protection for your mailbox, in addition to the Outbound Encryption and Inbound Shield systems. Full usability of the Account Takeover Protection module requires integration with Trustifi's outbound relay to be effective.

How It Works

Step 1: Establishing a Baseline

When Account Takeover Protection is enabled, Trustifi first creates a baseline of each user's normal email activity. This baseline includes (but is not limited to):

  • Normal activity hours

  • Devices used to send and open emails

  • Locations from which emails are opened

  • Domains that are in frequent contact

Step 2: Monitoring for Anomalies

After a baseline has been established, Trustifi continuously monitors user activity and looks for any activity that does not match the "normal" pattern for that user.
Examples of suspicious activity include:

  • An email being opened from a new or suspicious location

  • Emails sent from an unrecognized device

  • Activity outside of normal hours

  • Communication with unusual domains

Step 3: Alerting and Response

When suspicious activity is detected, it is logged and can trigger automated responses. Depending on the admin configuration, a suspicious activity event can:

  • Send a notification to the user

  • Send a notification to the admin

  • Send notifications to both the user and admin

  • Automatically block the user from sending emails

Users and admins can use the information from these alerts to check for other signs of suspicious activity, take steps to improve mailbox security, and block the user from sending emails until the potential security breach is resolved.