Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

URL Hunting

Prev Next

URL Hunting allows security teams to track and investigate link-click activity for emails scanned by Trustifi. It provides visibility into who clicked a link, when it was clicked, and from where, including device, browser, and location details.

This feature helps teams quickly assess exposure after a potentially malicious link has been accessed.

Enabling URL Hunting

To enable this feature, navigate to the Configuration page (Inbound Management > Inbound Shield > Configuration) and click on the toggle in the “URL Hunting” section.

When URL Hunting is enabled, Trustifi will re-write all links in received emails (similarly to On-click Scan) to enable tracking capabilities.

Viewing link click events

Navigate to the URL Hunting page (Inbound Management > URL Hunting)

By default, the page will display all of the recent clicked links when clicking on the “Get” button.

If you want to find a specific link, or create a more elaborate search, you can build a query by clicking on the query builder icon:

Here you can enter a specific URL, or search for all links from a certain domain.
You may also add more information such as the email’s sender, recipient mailbox, email subject, or Message-ID.

After you’ve build your query, you can click on “Get” to find only the link-click events that match your search.

The results display individual events of links being clicked. This means that if the same link was clicked by multiple recipients, or even by the same recipient multiple times, the page will display each time the link was clicked.

For each link-click event, you can see the following information:

  • Date and time the link was clicked

  • The URL of the link that was clicked

  • The recipient/user who clicked on the link

  • The device/browser and location from which the link was clicked

  • IP Address

  • Subject of the email containing the link

  • Sender of the email

Performing actions

From the “Actions” menu, you can perform several actions on the email containing the link or on the sender of the email:

  • Show Content: displays the content of the email containing this link

  • Blocklist Link: will add the URL to your global links blocklist

  • Blocklist Sender: will add the sender of the email to your global senders’ blocklist

  • Safe Preview: generates a safe, sandboxed view of the URL. Can be used to determine if the link is dangerous without the risk of malware or phishing.

  • Remove Email: deletes the email from the recipient’s mailbox.

  • Delete Tracking: deletes the URL tracking information.
    Note: this feature only works if you have an API integration between Trustifi and your O365 or Google mail server.