Updated Date: 07/07/2026
Configuring phishing detection on a URL
Configure phishing detection on a URL if you want the system to check for phishing attacks on the web page of the URL, and send an alert to the FPS Dashboard if an attack is detected.
-
On the Main tab, click Security > Fraud Protection Service > Anti-Fraud Profiles.
The Anti-Fraud Profiles screen opens.
-
From the list of profiles, select the profile on which you want to configure phishing detection.
The Anti-Fraud Profile Properties screen opens.
-
In the Anti-Fraud Configuration area, click URL List.
The URL List opens.
-
Click the URL on which you want to configure phishing detection (or click Add if you want to define a new URL with phishing detection).
The URL Properties screen opens.
-
In the URL Configuration area, select Phishing Detection.
-
Select the Enabled check box for Phishing Detection.
The Phishing Detection configuration options appear.
-
Select the Enabled check box for the Log credentials theft by a phishing site setting if you want the system to log the user names and text fields (not passwords) of users attacked by a phishing attempt on this URL.
Note: This setting does not appear if Web page copy detection (in the Advanced settings) is disabled.
-
Click Advanced.
-
Select the Enabled check box for the Web page copy detection setting if you want the system to detect whether the web page for this URL has been copied and send an alert to the FPS Dashboard if it determines that this happened.
-
Select the Enabled check box for the JavaScript removal detection setting if you want the system to detect whether JavaScript is missing from the web page of the URL and send an alert to the FPS Dashboard if it determines that this happened.
Note: This is part of the system’s phishing detection backup mechanism.
-
In the Location of Phishing Inline JavaScript and Image Injection field, select whether you want the phishing inline JavaScript and phishing image to be injected before or after the tag that you specify in the Tag field.
Note: The phishing inline JavaScript must be injected into the HTML after the main FPS JavaScript.
-
In the Input field types to include in alerts field, type HTML input field types (such as
textorcheckbox) on the web page that you want to include in alerts.For example, if you add
text, the system attaches the values of alltextinput fields on the web page to alerts. -
Click Save.
The URL configuration settings are saved.