How to configure Phishing and Malware protection in Zoho Mail Admin Console
The Phishing and Malware section in Zoho Mail Admin Console gives admins multiple controls to protect the organization from spoofing, fraudulent domains, display name impersonation, and malware-embedded email content. Admins can define actions for look-alike domains, protect key employee identities from being spoofed, and set up content-based spam checks for specific content types and HTML tags.
What are Cousin Domains in Zoho Mail and how do you block look-alike domains?
Cousin Domains are domain names that are very similar to any other valid domain name. If you expect a domain to send genuine emails, but want to mark an email from any other variations of the domain name as spam, you can add it in this section.
For example, if 'zylker.com' sends genuine emails, but emails from 'zylker1.com' needs to be processed for spam, you can add zylker.com here.
These variations are commonly used in phishing attacks to trick recipients into trusting fraudulent emails. Zoho Mail lets admins add trusted domains and automatically flag or quarantine emails arriving from any look-alike variations of those domains. Below are the steps to configure Cousin Domain in Zoho Mail Admin Console:
- Login to the Zoho Mail Admin Console.
- Go to the Security & Compliance menu, and select Phishing & Malware .
- Select the Cousin Domains option.
- In the Email Delivery Action dropdown, select the actions for emails that have look-alike domain names.
- If you select None, no action will be taken.
- If you select Move to spam, the email will be moved to the spam folder of the email recipient.
- If you select Move to quarantine, the email will be moved to the quarantine list, from where the admin will have to process if further.
- You can also choose to Include Internal Domains, which means that all of your organization's domains will undergo the cousin domains check by default. So, any domain name that is similar to yours will undergo the specified action.
- Now, click Add, enter the domain names for which cousin domain check has to be done, and click Add.
- You can also choose to include the domain names by click on Import, and selecting a CSV file which has all the domain names.
- All the added domains will be listed under Domain Name section.

When should you use Cousin Domain Protection in Zoho Mail?
The Cousin Domains feature is especially useful in cases where an email sender might try to trick recipients with a valid domain name.
For example, you might expect the domain webhosting.com to send valid emails to your org users. So, when an email arrives from user@vvebhosting.com, your org members might consider it legitimate, but the email sender has tricked the recipient by replacing the 'w' in webhosting.com with 'vv'.
In cases like these, the Cousin Domains feature comes into play.
What is Display Name Spoofing in Zoho Mail and how do you prevent it?
Display Name Spoofing occurs when an attacker sends an email using a trusted person's name, such as a CEO or manager, but from a completely different email address, tricking recipients into acting on fraudulent requests. Zoho Mail lets admins define which email addresses are authorized to use specific display names, so any email using that name from an unauthorized address is flagged or quarantined.
For example, consider the email address ceo@mydomain.com. You can ensure that if an email with the display name 'CEO' arrives from any other email address, the action defined by you is taken on this email address.
Follow the below steps to add a policy to prevent display name fraud:
- Login to the Zoho Mail Admin Console.
- Go to the Security & Compliance menu, and select Phishing & Malware .
- Select the Display Name Spoofing option.
- In the Email Delivery Action section, select the action for emails that have spoofed display names.
- If you select None, no action will be taken.
- If you select Move to spam, the email will be moved to the spam folder of the email recipient.
- If you select Move to quarantine, the email will be moved to the quarantine list, from where the admin will have to process if further.
- Now, click Add>>Add using email addresses.
- Enter the display name, and the email addresses that can be associated with this name, and click Add.

You will be able to see a list of the Display Names and the respective Email Addresses that you have added in the list.
For users with alias email address, you can quickly add the user's primary email address along with their alias addresses without having to manually enter each email address. Follow the below steps:
- Click Add > Search and add organization users.

- A list of your organization users appears as a pop-up window.

- Select the user you wish to add. If you wish to provide a different display name for the user, you can enter it in the Display name text box. Else, you can leave that box empty.
- Click Add with Aliases if you want to add the user's alias email address along with their primary email address.
- Click Add without aliases if you want to associate only the user's primary email address with their display name.

You will be able to see the Display Name and the respective Email Addresses that you have added in the list.
Furthermore, to avoid display name spoofing, Zoho Mail will show the sender's display name only if the sender is in your contacts or if you have had a previous conversation with the sender. Otherwise, only the sender's email address will be shown. For example, consider you get an email from rebecca@zylker.com who has Rebecca as her display name. The display name Rebecca will be shown only if rebecca@zylker.com is already in your contacts or if you have had a previous conversation with her. Otherwise, only the email address rebecca@zylker.com will be shown to avoid display spoofing.
What is Malware Processing in Zoho Mail and how does it protect against email-based threats?
Malware Processing in Zoho Mail Admin Console lets admins configure spam checks based on specific content types and HTML tags commonly used to embed malicious code in incoming emails. Admins can flag emails containing web bugs, JavaScript, macros, or bulk email markers, as well as emails with HTML tags such as frame, object, embed, or form, all of which are frequently used in malware attacks.
How to configure Content-based Spam Settings in Zoho Mail Admin Console
The Content-Based Spam Settings section lists four high-risk content types:
- Web Bugs
- Bulk emails
- JavaScript
- Macros
Admins can select these options to automatically move matching incoming emails to spam. This is particularly useful for blocking emails that carry hidden tracking elements or executable scripts designed to compromise user devices or extract sensitive data.
Follow the below steps to configure Content-Based Spam Settings:
- Login to the Zoho Mail Admin Console.
- Go to the Security & Compliance menu, and select Phishing & Malware .
- Select the Malware Processing option.
- In the Content-based Spam Settings option, you can see 4 content types (Web Bugs, Bulk emails, JavaScript, Macros) listed.
- Select the types that you think might be harmful, and emails containing the content types selected will be moved to spam.

How to configure HTML Tags-based Spam Check in Zoho Mail Admin Console
The HTML Tags-Based Spam Check section lets admins flag incoming emails containing specific HTML tags like frame, object, embed, and form, that are commonly used to embed malicious content or redirect users to phishing sites. Selecting any of these tags ensures that emails containing them are automatically moved to spam before reaching users' inboxes.
Follow the below steps to configure HTML Tags-Based Spam Check:
- Login to the Zoho Mail Admin Console.
- Go to the Security & Compliance menu, and select Phishing & Malware .
- Select the Malware Processing option.
- In the HTML Tags-based Spam Check option, 4 tags (Frame, Object, Embed, Form) will be listed.
- Select the tags that you think might be harmful, and emails containing these tags will be moved to spam.

Note:
All the features in the Phishing & Malware section will be available only for paid account users.
Frequently Asked Quesitons (FAQs)
What is the difference between Cousin Domain protection and Display Name Spoofing protection in Zoho Mail?
Cousin Domain protection detects and flags emails from domain names that closely resemble a legitimate domain. For example, zylker1.com impersonating zylker.com, and processes them based on the admin-defined delivery action. Display Name Spoofing protection focuses on the sender's display name rather than the domain. Admins can map specific display names such as a CEO or manager to authorized email addresses, so any email using that name from an unauthorized address is automatically flagged.
What happens to emails that match a Cousin Domain check in Zoho Mail, are they deleted?
No, emails that match a Cousin Domain check are not automatically deleted. Admins can choose one of three delivery actions when configuring the Cousin Domain settings: None (no action taken), Move to Spam, or Move to Quarantine. Emails moved to quarantine must be reviewed and processed by an admin before any further action is taken.
Can a Zoho Mail admin protect against CEO or VIP impersonation in emails?
Yes. The Display Name Spoofing feature in Zoho Mail Admin Console lets admins add the display names of key employees such as a CEO, manager, or finance head, along with their authorized email addresses. Any email using one of these display names from an unauthorized address is automatically flagged or quarantined. This protects users from business email compromise and VIP impersonation attacks.
What content types and HTML tags can Zoho Mail flag as malware in incoming emails?
Zoho Mail's Malware Processing settings allow admins to flag four content types: web bugs, bulk emails, JavaScript, and macros. Admins can also flag four HTML tags: frame, object, embed, and form. Any combination of these can be selected from the Admin Console, and emails containing the selected content types or tags will be automatically moved to spam before reaching users' inboxes.
Does Zoho Mail scan outgoing emails for bulk or promotional content?
Yes. In addition to the admin-configured controls for incoming threats, outgoing emails in Zoho Mail are automatically scanned for bulk or promotional content. This built-in scanning helps safeguard your organization's domain reputation by preventing your domain from being flagged or blacklisted by recipient mail servers.
Related Pages
Spam Control Settings | Spam Control Lists | Spam Quarantine