
Build rules on individual URL Risk signals, link shorteners, redirect chains, reported URLs, brand impersonation, and domain age.
URL Risk scores every link in a message, but until now rules could only act on the
overall score. The individual signals behind that score are now available as rule
conditions, the same way Unicode Spoofing exposes its per-signal flags.
In the rule builder, pick the URL Risk policy and condition on any of its signals:
Link shortener — the message contains a shortened URL.
Redirect count — the longest redirect chain behind any URL. For example, reject
when it is greater than 3.
Reported URL — a URL is on a threat intelligence blocklist.
Brand impersonation — a URL imitates a known brand's domain.
Suspicious characters — a URL uses look-alike or unusual characters.
Domain age (days) — the youngest domain in the message. Catch freshly registered
phishing domains with a "less than 30" condition.
Signals cover every URL in the message, and URLs on your allowlist are ignored. The AI
rule assistant knows the new fields too, so "reject links with more than 3 redirects"
writes the rule for you.