Most breaches that start with email involve one of two things: a link that leads to a fake sign-in page or malicious download, or an attachment that carries malware. Email security products promise to deal with both through features usually called sandboxing, detonation, safe links or link protection. The terms sound technical, but the ideas are straightforward, and understanding them helps you judge what you are paying for and what staff training must still cover.
A sandbox is an isolated environment where software can run without touching your real systems. With attachment sandboxing, the email security service opens a suspicious file inside a disposable virtual machine, which is why vendors often call it detonation.
A message arrives with an attachment, such as a document, spreadsheet, PDF or compressed file.
The service checks it first against known threats and reputation data.
If the file is unknown or suspicious, it is opened in the sandbox.
The service watches what happens: Does it try to run hidden code, contact unusual servers, change system settings or download other software?
If the behavior looks malicious, the message is blocked or quarantined. If it looks clean, it is delivered.
This approach catches threats that signature-based antivirus has never seen, because it relies on behavior rather than a known fingerprint.
Safe-link features, sometimes called URL protection, rewrite the web addresses in incoming messages so they pass through the security provider before the user reaches the destination.
When the message arrives, each link is replaced with a version that points to the provider.
When a user clicks, the provider checks the destination at that moment, comparing it to reputation data and sometimes scanning the page content.
If the site is known to be malicious, the user sees a warning page instead.
Checking at click time matters, because attackers often send links that appear harmless on delivery and are switched to a malicious page hours later.
Sandboxing and link protection reduce risk, but they are not guarantees. Knowing the weak points helps you plan around them.
Delayed activation. Some malware waits several minutes or looks for signs of a sandbox before acting. Attackers design files to behave normally when watched.
Password-protected files. If the password is in the email body, a sandbox may not be able to open the file, although some services try common passwords.
Links inside images or QR codes. A link hidden in a picture or QR code may not be rewritten or scanned, and a phone scanning it may bypass desktop protections.
Fresh and compromised sites. A newly created or legitimately hacked website has no bad reputation yet.
Human-gated pages. Fake sign-in pages may only appear after a person completes a challenge, which automated scanners cannot pass.
Detonation takes time, from seconds to a few minutes. Some organizations accept short delays for better protection, while others deliver mail first and remove it afterward if it proves malicious. Ask your provider how this works in your configuration.
Rewritten links can look strange, break some tools, and confuse staff who check where a link goes. Staff may also click a rewritten link on the assumption that it must be safe because the provider handles it. That belief is not accurate, and training should say so.
Protection applies only to mail that flows through the service. Messages sent through other channels, such as text messages, collaboration apps, personal email or social media, may bypass it. Attackers also send messages from accounts they have already compromised, which look trustworthy.
Turn the features on. Many email platforms include them, but they are not always enabled by default or included in basic licenses. Check your plan.
Apply them to everyone. Include executives and shared mailboxes, which attackers target.
Enable multi-factor authentication. If a user does enter a password on a fake page, a second factor can stop the attacker.
Train staff. Teach people to pause on unexpected requests, verify through another channel, and report suspicious messages with one click.
Review reports. See what was blocked, what users clicked, and which clicks were allowed.
Plan for failure. Know how to reset credentials, revoke sessions and search for and delete a malicious message from all mailboxes.
Ask providers what file types they detonate, how long it takes, whether links are checked at click time, how they handle QR codes and password-protected files, and how you can see the results. Request a trial and measure with real messages.
UnityCare IT treats email security as one layer among several, alongside authentication, training, endpoint protection and tested backups. If you want help checking whether the protections you already pay for are actually turned on, we are glad to review the configuration with you.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172