This article explains how Cloud App Security (CAS) scans URLs within emails. It also defines why in some cases CAS is suspected to click URLs within emails.
Cloud App Security scans emails in the following order:
- CAS will scan the URLs in the mail body and the URLs in the attachment (if feature is enabled) using Web Reputation Service (WRS).
- CAS checks customer's policy settings and WRS result.
- URLs will be scanned by Dynamic URL Scanning (if feature is enabled).
Dynamic URL Scanning, is a feature leveraged by CAS to detect phishing websites. Dynamic URL Scanning will try to crawl the URL's website, and is responsible in clicking the URLs for evaluation purposes. This is one reason why CAS is suspected to click URLs within emails.
- CAS will scan the email using Computer Vision Technology.
- If the URL is not rated/detected by WRS, Dynamic URL Scanning and Computer Vision Technology, CAS will send the URL with payload to Virtual Analyzer (if the feature is enabled).
To prevent CAS from "clicking" the URLs, refer to the "How to prevent CAS from "clicking" the URL in Phishing Awareness Campaign mails?" section of Frequently Asked Questions (FAQs) and How-Tos about the Features of Cloud App Security (CAS).