Documentation Index

Fetch the complete documentation index at: https://help.silentpush.com/llms.txt

Use this file to discover all available pages before exploring further.

Email Impersonation

Prev Next

Email Impersonation Query

The Email Impersonation query detects domains that target organizations via MX (Mail Exchange) record manipulation, in which attackers disguise malicious emails as originating from legitimate mail servers.

Execute an Email Impersonation Query

    1. From the navigation menu, select Reconnaissance > Email Impersonation.

  1. Enter a domain name in the Domain Name box (wildcards are not supported).

  2. (Optional) Click Save to store the query for future use.

  3. Click Search.

Understand Email Impersonation Results

Results are displayed in an Explore table with the following columns:

  • Query: Domain the result pertains to.

  • Risk Score: Silent Push Risk Score.

  • Answer: MX record.

  • First Seen: Date and time the MX record was first observed.

  • Last Seen: Date and time the MX record was last observed.

  • MX Hash: Hash value of the MX record.

  • MX Server Density: Density of the MX server.

  • WHOIS Created Date: Domain creation date.

  • WHOIS Registrar: Registrar of the domain.

Monitor and Save Results

Monitoring

Click Monitor on the results screen, enter a Monitor name and Description, then click Save to receive daily email alerts.

Save to a Feed

  1. Left-click one or multiple results.

  2. Select Save to in the top-right of the results screen.

  3. Use the contextual menu to save to an existing or new collection/feed.