Summary
Why Trusted Webmail Domains Can Still Deliver Email Threats
An email arrives from a familiar webmail provider. The sending infrastructure is legitimate, and there are no suspicious attachments or malicious links. Yet the message asks an employee to purchase gift cards, change payroll details, or respond to a fraudulent financial request. These attacks expose a challenge for email security: reputable services can carry dangerous messages. Checking where an email originated provides valuable information but understanding whether the message itself deserves trust requires additional context.
Fortra developed the WebMail Catcher (WMC) model to address this challenge. WMC focuses on messages originating from personal email services, including webmail providers and Internet Service Providers (ISPs), to identify potentially malicious emails and spam that can escape defenses focused on sending infrastructure.
Personal email services support a wide range of legitimate communications. Employees send documents from their personal accounts, independent professionals contact customers, and individuals communicate with businesses. Blocking messages simply because they originate from these services would disrupt routine work.
Attackers can use the same infrastructure to deliver social engineering scams. When the attack depends on persuading a recipient to act, there may be no harmful file or website to detect. The warning signs instead emerge from the language, sender identity, communication history, and broader sending behavior.
The Model
The WMC is a classical Machine Learning (ML) model that combines these signals together through feature engineering. It classifies each eligible message into one of three categories:
Malicious: Potentially dangerous emails.
Suspicious: Unwanted messages, such as aggressive marketing, that are not necessarily dangerous.
Safe: Messages that cannot be considered malicious or suspicious.
The features can be grouped into four main types:
Language and sender information: Natural Language Processing (NLP) models provide signals about subject-line topic, suspiciousness, and attention-seeking language, alongside classifications of display names.
Communication history: User Profiling Infrastructure (UPI) features capture previous inbound and outbound interactions, including counts and age-related measures. These help the model evaluate the relationship between sender and recipient.
Sending volume and campaign activity features describe sending volumes, the number of organizations receiving similar messages, and whether an email belongs to a detected campaign.
Message structure and metadata: Additional signals include message structure, URL counts, attachment presence, and text-based comparisons involving sender and recipient information.
These signals give the classifier context that any individual indicator would lack. An unfamiliar sender is not automatically malicious, and an attention-grabbing subject line can appear in legitimate correspondence. Their significance depends on the concurrent evidence found in the message.
Examples
Consider an illustrative gift card scam. A personal email account sends an employee a message with the subject:
“Need a quick favor”
followed by a request to purchase gift cards. The provider’s reputation offers little insight into the request. However, limited communication history, suspicious language signals, and evidence of similar messages reaching other organizations could collectively support a malicious classification.
Now consider an employee sending a document from a personal account to a work address. That message also originates from a webmail provider, but its communication history and sender–recipient information may provide evidence of a legitimate interaction. WMC’s combination of features is designed to help distinguish such everyday exchanges from suspicious outreach.
Model Performance
The model was trained on an internally curated and challenging dataset. By adding a mechanism to reduce False Positives (FPs), we were able to push the model’s precision in production to over 99%. The model has a “weighted” impact on the message’s trust score. High-confidence malicious classifications drop the score to the lowest range, while spam and lower-confidence classifications receive a milder negative score adjustment. This allows the system to distinguish the model’s assessment from the action supported by that assessment.