Skip to content
Avanet

Sophos Email: configure Impersonation Protection and VIP protection

Impersonation Protection detects inbound messages pretending to come from well-known brands, senior people inside the organisation, or important external contacts. These BEC messages often contain neither malware nor a conspicuous link. The protection therefore complements spam, malware, and sender checks; it doesn’t replace them.

Safe quick path: first create a verified VIP list under Global Settings > Products and Services > Email > Business Email Compromise > Impersonation. Then open the relevant Email Security Policy under My Products > Email Security > Policies, check its scope and order, and configure VIP Impersonation, Brand Impersonation, and General Impersonation. Quarantine or a smart banner is safer than immediate deletion during a pilot. Finally, compare legitimate and suspicious test cases in Message History.

Prepare the scope, starting state, and test plan

Before making a change, you need an owner for the VIP list, a confirmed list of internal and external VIPs, and known legitimate name collisions. Record the following in the change:

  • policy name, Inbound direction, and assigned users, groups, and domains;
  • policy order, Policy is enforced status, and rules above it;
  • status and actions for VIP Impersonation, Brand Impersonation, General Impersonation, and Aggressive Mode;
  • current smart-banner actions and subject tags;
  • relevant SPF, DKIM, and DMARC results and the visible sender-check sequence;
  • a pilot recipient, a control recipient, and expected results;
  • rollback: restore the previous actions, order, and enforcement status.

Policy assignment is part of the protection. Correct impersonation settings don’t help when a higher-priority rule or another scope applies. The Sophos Email Security policy guide explains how scope and priority are evaluated.

New domain/sender can also add a classification. Its learning period is 0 to 90 days, defaults to 14 days, and starts with the sender’s first inbound message. Changes affect newly observed senders. This check and SPF, DKIM, or DMARC are related sender signals; they are not the same as a VIP, brand, or general impersonation detection. See the sender authentication and smart banner guide for those controls.

Warning:

Never use an exception for a legitimate sender to turn off malware scanning. Establish the detection, policy match, and raw-header evidence first; then, at most, correct the specific false-positive check within the narrowest necessary scope.

Manage the VIP list in a controlled way

The VIP management list is shared by domains protected in the same Sophos Fusion (formerly Sophos Central) account and holds no more than 1000 email addresses. Internal VIPs are people in your own organisation who are especially likely to be impersonated. External VIPs are important people at suppliers, customers, or partners. You can’t add an internal VIP as an external VIP.

Add internal and external VIPs individually

  1. In Sophos Fusion, open the Global Settings icon and go to Products and Services > Email > Business Email Compromise.
  2. Open Impersonation and click Add VIP > Add VIPs in the VIP management list.
  3. For an internal person, leave Internal VIPs selected, search by name or email address, and click Save.
  4. For an external contact, select External VIPs, enter the verified name and email address, and click Save.
  5. Confirm that the name, address, and type appear correctly in the list.

Help find internal VIPs searches a connected Active Directory service for high-risk users. Complete AD data such as job titles improves its suggestions. Results are a selection aid, not an automatically authorised VIP list; verify each person before clicking Add.

Import, export, or delete using CSV

For many entries, use Add VIP > Import VIPs, download the templates first, and retain their format. The CSV must use UTF-8. Internal entries contain only an email address; external entries contain both a name and an email address. Choose the completed file under Import VIP list > Browse, then start Import.

Warning:

Replace existing list with this import permanently removes every existing entry. Export the complete list first, check the entry count and a sample, and proceed only when a full replacement has been explicitly approved.

When exporting, select individual VIPs or the entire list deliberately and retain the CSV for rollback. To delete, select the internal or external VIPs, click Delete, and confirm Delete again in the dialog. After an import or deletion, check the total, types, and a sample of critical entries directly in Sophos Fusion.

Configure Impersonation Protection in the policy

Under My Products > Email Security > Policies, open the Email Security Policy intended for the pilot. Before changing it, check its internal and, where relevant, external scope, Inbound direction, order, and Policy is enforced status. Then complete the configuration in this order:

  1. Turn on VIP Impersonation and select Add banner or Quarantine as the pilot Action.
  2. Optionally turn on Aggressive Mode when the small pilot group explicitly needs greater sensitivity.
  3. Turn on Brand Impersonation and select its pilot action.
  4. Turn on General Impersonation and select its pilot action.
  5. Wherever Add banner is selected, turn on the supported Block sender and/or Report messages to Sophos options as required. For Tag subject line, enter a prefix of no more than 65 characters.
  6. Turn on Policy is enforced if the pilot policy isn’t already active, then click Save. Reopen the policy and confirm that the toggles, actions, and options were retained.

VIP Impersonation normally combines VIP-name matching, machine learning, and anti-phishing heuristics. A name match alone therefore doesn’t necessarily produce a detection. Aggressive Mode applies only to VIP Impersonation and decides solely from VIP-name matches, including fuzzy variants, without machine learning or heuristics. It also increases false-positive risk around common names, so check assistants, recruiters, ticketing platforms, and other legitimate pilot senders that use VIP names in their display name.

Brand Impersonation detects imitation of frequently attacked brands or domains. Sophos scans for the most abused brands by default, even with an empty VIP list. This workflow doesn’t add a custom brand as a VIP; add important people at a partner as external VIPs instead. General Impersonation uses machine learning and anti-phishing heuristics to identify suspicious imitation without a matching VIP name or frequently attacked brand.

In addition to Add banner and Quarantine, the available actions include Tag subject line and Delete; Delete removes the message immediately and should be used in production only after stable acceptance testing and a documented incident process. Deliver is available only for General Impersonation.

Use smart banners and quarantine safely

With Add banner, you can offer Block sender and Report messages to Sophos. Block Sender opens a confirmation page for the user’s personal block list. Report submits the message to SophosLabs and helps improve detection. HTML messages show a visual smart banner; plain-text messages show the same text at the beginning of the body.

A banner is a warning and reporting aid, not a safety verdict. Only administrators can release quarantined impersonation messages, and by default users can’t see them in either the Self Service Portal or quarantine summary. Put a monitored administrator review and release process in place before using quarantine in production.

Validate the effect under controlled conditions

Don’t test by impersonating a real executive to production users. Use an approved test identity, an isolated pilot recipient, and harmless content. Record the time, sender, recipient, display name, and Message-ID for every send:

  1. legitimate mail from an internal VIP through the intended sending route;
  2. legitimate mail from an external VIP with the correct name and sender;
  3. only when Aggressive Mode is enabled, a controlled VIP-name match from an untrusted test address;
  4. normal legitimate brand mail and a harmless, approved brand variation as an observation case;
  5. a harmless, approved variation for General Impersonation as an observation case;
  6. a legitimate message with known SPF, DKIM, and DMARC results, plus the same cases to the out-of-scope control recipient.

First reopen the saved policy and confirm its scope, order, enforcement, three toggles, actions, banner options, and the recorded Aggressive Mode state. Then open each message in Message History and compare its policy match, recipient, category, sender-check or authentication details, and action with the test record. For banner delivery, verify rendering and offered actions in HTML and plain text. For quarantine, have an administrator verify visibility and the release route.

The pilot passes when the saved configuration is reproducible, legitimate messages follow the expected path, the control recipient isn’t unexpectedly affected, and every message actually classified as VIP, Brand, or General Impersonation receives the action selected for that category. Only the name match with Aggressive Mode enabled is a targeted VIP-detection test here. Synthetic Brand and General samples can remain clean because machine learning and heuristics decide their classification; a non-detection isn’t a configuration failure or a reason to weaken other controls. For a tracked assessment of an unexpected result, open a Sophos Support case and provide the test record.

Investigate misclassifications and missed detections

  • An internal VIP can’t be added as external: this is expected. Use the internal directory entry and check the address or Directory Sync.
  • CSV is rejected or entries are missing: check UTF-8, the unchanged template format, internal address fields, external name-and-address fields, and the 1000-entry limit. After an attempted replacement, restore the export before trying further imports.
  • Legitimate mail triggers VIP Impersonation: first determine whether Aggressive Mode is enabled and whether an exact or fuzzy name match occurred. Then record policy scope, sender, display name, raw headers, and authentication. Don’t create a broad domain allow rule.
  • Expected VIP detection is absent: a name match alone needn’t block in standard mode because machine learning and heuristics also decide. Check VIP type and address, policy enforcement, scope, order, and the actual Message History record.
  • Brand or General Impersonation behaves unexpectedly: confirm the category in Message History rather than inferring it from the visible name. An empty VIP list doesn’t turn off brand protection.
  • Wrong action or missing banner: check which policy matched first, which detection supplied the category, and whether the message was HTML or plain text. Evaluate Sender Authentication and New domain/sender separately.

For a false positive, preserve the Message-ID, timestamp, sender, recipient, policy name, category, action, and raw headers, then select Report as Not Spam in Message History when offered. Report a delivered suspicious message there with Report as Spam or use Report in the smart banner. Also send a missed targeted spear-phishing or BEC message as a complete RFC-2822 attachment to spearphish@labs.sophos.com; send ordinary spam, fraud, and phishing samples to is-spam@labs.sophos.com. Don’t send the same sample to both addresses. These sample mailboxes don’t reply or create a trackable case. If you need status or a documented assessment, also open a Sophos Support case and include the Message-ID, submission time, and sample destination.

For rollback, restore the documented previous policy actions, order, and, where necessary, enforcement status, then save. Restore the VIP list only from the last verified export. Messages already quarantined remain in quarantine after the policy change; an administrator must review and release or delete each one individually. Don’t disable malware scanning or other protection layers as part of the rollback.