CanIPhish can conduct manual or fully automated AI-powered scans of reported emails to help administrators with the burdensome task of analysing and classifying reported emails.
In this support article, we'll walk through everything you need to know about CanIPhish's AI-Powered Email Analysis Engine.
Table of Contents:
How It Works
CanIPhish has developed a fine-tuned AI model that's designed to accurately analyze and categorize emails based on a range of detection capabilities. As part of the analysis, the following is performed:
-
Sender Address Analysis: Check standard email security signals that many organizations use to prove an email really came from a domain.
- SPF, DKIM, and DMARC results are extracted from the email headers.
- If these checks fail, risk increases because spoofing is more likely.
- Detect cases where the email was forwarded, because forwarding commonly breaks SPF and can make a legitimate email look suspicious.
- Recognize when an email is authenticated as genuine internal mail (e.g., a DMARC pass, or a message sent within your own Microsoft 365 tenant) from one of your verified domains, reducing false positives on legitimate internal email.
- Recognize legitimate system notifications, such as Microsoft 365 quarantine digests. These notifications quote details of the suspicious emails they report on, and are assessed accordingly rather than being mistaken for phishing themselves.
-
Infrastructure Analysis: Check sender infrastructure against threat intelligence.
- Look up the sending IP reputation to confirm if the originating mail server is known for abuse.
- Look up the sending domain's reputation to confirm if the email address domain is associated with spam/phishing behavior.
- Check the sending IP and domain against live malware threat intelligence, refreshed hourly.
- Check how recently the sender's domain was first registered. Domains registered only days or weeks before they email you are heavily over-represented in phishing, so a very new sender domain raises risk.
-
Link Analysis: Check links embedded within the email against threat intelligence and safely visit them in an isolated cloud sandbox.
- Extract URLs and their hostnames to then confirm if the domains appear in known malicious website listings.
- Unwrap security-gateway link rewrites (e.g., Microsoft Safe Links, Proofpoint URL Defense) so the analysis sees the link's true destination rather than the rewritten wrapper.
- Check links and link hosts against live malware distribution listings, refreshed hourly.
- Detect when a link's visible display text shows a different domain than its actual destination — a common phishing deception technique.
- Extract and analyze links hidden inside QR codes, a technique commonly used to bypass link scanning.
- Visit each suspicious link in an isolated cloud sandbox to see what it actually does — following the full chain of redirects and capturing a screenshot of every page, including the final landing page. This catches brand-new phishing pages that have no reputation history yet.
- Detect credential-harvesting pages, fake sign-in forms, brand impersonation, and forced file downloads on the pages a link leads to.
- Recognize when a page tries to cloak or block inspection, so a link that merely looks clean on a visit isn't automatically treated as safe.
- Identify who hosts a link's destination and how recently that destination's domain was registered.
- Resolve a single verdict for each link — malicious, suspicious, benign, or inconclusive — by combining every signal (reputation, community intelligence, the sandbox visit, hosting, and display-text checks), with a plain-English explanation of how the verdict was reached.
-
Attachment Analysis: Scan attachments for risky files and known malware.
- Categorize attachments into high, medium, and low risk types based on the kind of file.
- Spot filename disguises used to make a dangerous file look harmless — double extensions (invoice.pdf.exe), right-to-left-override text tricks, look-alike character substitutions, and a mismatch between a file's true type and its declared type.
- Inspect inside the file for dangerous active content — auto-executing macros (VBA), DDE, PDF actions (auto-open, embedded JavaScript, launch actions), embedded executables, and malicious shortcut (.lnk) files.
- Flag documents that silently reach out to a remote server or attempt to harvest your credentials, such as remote-template injection or forced-authentication references.
- Detect files that hide a program inside an apparently harmless file (for example, an executable concealed in something claiming to be an image).
- Safely unpack archives (zip, 7z, rar), including nested archives, and inspect everything inside.
- Extract and analyze any links embedded inside documents, assessing them alongside the email's other links.
- Identify known malware through signature-based scanning (ClamAV), with signatures refreshed regularly.
- Render documents to page images inside the sandbox so you can preview exactly what an attachment looks like — without ever opening it on your own device.
- Produce a clear verdict for each attachment — malicious, suspicious, or clean — listing the specific items that were flagged.
-
Sentiment Analysis: Identify the intent of the email and the action being requested of the recipient.
- Identify whether the sender is imposing urgency or pressure on the recipient to act fast.
- Identify whether the sender is requesting the recipient to keep the conversation a secret.
- Identify requests for sensitive information such as passwords and payment information.
- Identify requests for money, such as changing bank details or requesting gift cards.
-
Relationship Analysis: Identify what relationship the sender has with the recipient.
- Identify if an email address at the sender's domain has been successfully reported by another user for sending spam or phishing.
- Identify if the sender and recipient have been engaged in a prolonged two-way conversation, or if communication is one-sided (e.g., the recipient has never responded).
- Identify if the sender has just all of a sudden begun emailing the recipient, or if there is evidence of ongoing email exchanges from at least 1 month prior.
- Identify if the sender (or another sender at the same domain) has previously been reported by another user for sending spam or phishing. For authenticated senders on your organization's own verified domains, this check matches the exact sender address, so one mis-categorized report can't flag all internal email.
-
Impersonation Analysis: Check for external senders attempting to masquerade as an internal employee.
- Identify suspicious sender display names (e.g., HR, Procurement, Executive).
- Identify whether the sender domain is internal or external to the organization (cross-referencing against verified domains).
- Identify whether the email body mentions manager or executive names (cross-referencing against employee lists).
- Identify a mismatch between the sender email address and the reply-to address.
- Identify lookalike sender domains that closely resemble your verified domains (e.g., character substitutions like "yourc0mpany.com" impersonating "yourcompany.com").
- Identify sender display names that match the names of your managers or executives while the email originates from an external domain.
- Identify senders whose email address is crafted to impersonate a government body or public authority — for example, a local-part made to look like an official ".gov" address — when the sending domain doesn't actually belong to that authority.
-
Community Threat Intelligence: Leverage confirmed verdicts from across the CanIPhish customer base.
- When security administrators at multiple other customer organizations have independently confirmed a sender, domain, or link as phishing or spam, that intelligence raises the risk score for matching emails reported in your organization.
- Only human triage verdicts contribute to this intelligence — AI verdicts never do — and contributions are accepted only from organizations on qualifying subscriptions, protecting the dataset's integrity.
Important Note: Relationship Analysis can only function if email quarantine functionality is set up. The quarantine integration provides the ability to search the user's inbox for metadata on prior email exchanges between the sender and recipient. The results of these searches are captured as a number of true/false flags, which are then provided to CanIPhish's AI model as context (i.e., prior raw emails aren't processed by CanIPhish's AI model, just true/false flags of whether certain relationship attributes were observed).
Attack Pattern Recognition
The analysis types above each look at one aspect of an email, and in isolation any single observation is often unremarkable. A recently registered sender domain is not suspicious by itself — organizations register new domains constantly. Nor is a request to update payment details, or an email from someone the recipient has never corresponded with before. Judged individually, each of these appears in a large volume of ordinary business email.
What distinguishes an attack is the combination. CanIPhish’s Email Analysis Engine therefore runs an additional layer that looks for known attack patterns — specific groupings of signals that, together, describe how a real attack is actually assembled. A brand-new sender domain, a payment-related request, and no prior relationship between sender and recipient is a recognizable shape, and it is a far stronger indicator than any of those three facts on its own.
When a pattern matches, it raises the email’s risk score and is recorded in the Scoring Reasons shown with the analysis, so administrators can see plainly which pattern was recognized and why. These patterns are maintained by CanIPhish and are evaluated automatically — there is nothing to configure, and they are continuously reviewed against real reported email so that patterns which stop earning their place are retired.
We deliberately don’t publish the specific signal combinations behind each pattern. Documenting the exact criteria would primarily serve attackers looking to structure campaigns that avoid them.
Email Analysis Output
When an email is analyzed, the following information is made available:
-
Risk Score: A score ranging from 0-100, with 0 representing a non-malicious email, and 100 representing the presence of many malicious indicators. Additionally, an AI Classification is provided, which can be one of four classifications, notably:
- Unknown: An unknown classification is provided if the AI Analysis Engine is unable to accurately determine what the email should be classified as.
- Benign: A benign classification is provided if the AI Analysis Engine believes the email is legitimate or non-malicious.
- Spam: A spam classification is provided when the email is unwanted commercial mail that is not attempting to deceive the recipient — such as cold sales outreach, marketing, lead generation, recruitment, or promotions — where the sender genuinely is who they claim to be.
- Malicious: A malicious classification is provided when the email attempts to deceive the recipient in order to obtain something — such as credential theft, payment or invoice fraud, impersonation of a person or brand, malicious attachments or links, or fake security, delivery, and account notices. Deception is what separates malicious from spam: an email that misrepresents who it is from, what a link or attachment is, or what happens when the recipient acts is classified as malicious no matter how much it resembles ordinary marketing.
- Authentication: An overview of whether SPF, DKIM, and DMARC authentication passed or failed, what domain email authentication was performed against, and the IP address that initially sent the email.
- AI Summary: An overview of key information that has been extracted from the email based on the cumulation of all data available, including analysis of email headers, email body, and email attachments.
- Scoring Reasons: A list of notable items that have impacted the risk score assigned to the email.
- Link Analysis: For each link found in the email, a single resolved verdict (malicious, suspicious, benign, or inconclusive) and the evidence behind it — including the screenshots captured while the link was visited in the sandbox (the full redirect journey), the hosting and domain-registration details, and any reputation or community-intelligence matches.
- Attachment Analysis: For each attachment, a verdict (malicious, suspicious, or clean) and the specific items flagged — for example, an auto-executing macro, a PDF auto-open action, or a known malware signature — together with a safe rendered preview of the document's pages.
Reported Email Analysis Configurations
These settings can be found by navigating to Phish Triage, then clicking the Phish Triage Settings button and selecting the Analysis tab.
Manual vs. Automatic Analysis
CanIPhish's Email Analysis Engine can be configured in one of two states:
- Manual Analysis: Administrators can initiate the analysis of an email on an individual basis. The analysis can be initiated by viewing the email report, going to the analysis tab, and clicking the "Run Analysis" button.
- Automatic Analysis: From the time of activation, all email reports will be automatically analyzed by CanIPhish's Email Analysis Engine, meaning administrators can immediately see the results of the analysis upon viewing the email report.
Automatic Attribution
CanIPhish's Email Analysis Engine can automatically attribute reported emails as Actual Spam or Actual Phishing if specific conditions are met:
- Automatically Attribute AI-Detected Spam: If the AI Analysis Engine classifies the email as spam, the email report will be automatically attributed as Actual Spam.
- Automatically Attribute AI-Detected Phishing: If the AI Analysis Engine classifies the email as malicious, the email report will be automatically attributed as Actual Phishing.
Automatic attribution relies on the AI classification alone. Both settings previously also required the email's Risk Score to exceed a threshold you configured; that threshold has been removed, because the classification already accounts for the score when the Analysis Engine reaches its verdict. Whether an attributed email is then quarantined remains controlled separately by your per-attribution quarantine settings.
Comments
0 comments
Please sign in to leave a comment.