Email Security

URL Sandbox Explained: Secure Link Isolation for Email Security


Quick Summary: Every link in your email is a potential threat. URL sandboxing lets you open any link inside an isolated, containerised browser session so threats never reach your device or network. CyberCheck360 takes this further with real-time blacklist checks, domain age analysis, organizational allow/block lists, and full zero-trust control over every link your team clicks.


Table of Contents

  1. What is URL Sandboxing?
  2. The Problem with Links in Email
  3. How Link Rewriting Works
  4. CyberCheck360 Secure Link — How It Works
  5. What Happens When a User Clicks a Link
  6. Raising a Local Browsing Request
  7. Zero Trust Link Policy for Your Organization
  8. How to Access the URL Sandbox
  9. Threats Stopped by URL Sandboxing

What is URL Sandboxing?

URL sandboxing is the practice of opening a web link inside a secure, isolated environment separate from your local browser, device, and network. so that any malicious content the link contains cannot affect you.

When a link is opened in a sandbox, the page loads inside a contained session. Any scripts, downloads, exploits, or trackers that execute do so within that isolated container. Once the session ends, everything is discarded. Nothing persists. Nothing reaches your device.

Traditional antivirus and email filters rely on known threat databases to block malicious links. URL sandboxing goes a step further, it lets you safely interact with and inspect a link in real time, even if the threat is brand new and not yet on any blacklist.

CyberCheck360 URL Sandbox tool where users can paste any link and open it in an isolated sandbox session for safe browsing


Email remains the number one delivery method for cyberattacks. The vast majority of ransomware, phishing, and credential theft attacks begin with a single email and a single click.

Links embedded in emails are particularly dangerous because:

  • They can redirect to a different destination after the email is delivered (time-of-click attacks)
  • They can trigger drive-by downloads that execute malware the moment a page loads
  • They can point to convincing phishing pages that steal credentials
  • They can contain tracking pixels and fingerprinting scripts that profile the recipient
  • They may come from trusted domains that have been compromised

Blacklist-only approaches cannot stop these threats. A newly registered phishing domain, a compromised legitimate domain, or a redirect chain that routes through clean infrastructure will pass straight through a reputation check.

URL sandboxing addresses this at the point of click, not just at the point of delivery.


Link rewriting is one of the most common techniques used by email security platforms to intercept clicks before they reach the destination URL.

When an email passes through a security gateway that uses link rewriting:

  1. Every URL in the email body is replaced with a proxy URL pointing to the security vendor's infrastructure
  2. When the user clicks the link, the request goes to the proxy first, not the destination
  3. The proxy performs a real-time reputation check on the original URL
  4. If the URL passes, the user is redirected to the destination in their local browser
  5. If it fails, the user is blocked or warned

Standard link rewriting only checks reputation at the moment of click. Once the check passes, the user lands on the destination page in their own browser, on their own device. If the page contains a zero-day exploit, a drive-by download, or malicious JavaScript, the user is now fully exposed.

This is the gap that URL sandboxing fills.

Comparison of traditional link rewriting vs CyberCheck360 secure link isolation showing how CyberCheck360 keeps threats contained inside an isolated sandbox instead of redirecting users to their local browser


CyberCheck360 goes beyond traditional link rewriting. Instead of simply checking a link and redirecting the user to their local browser, CyberCheck360 intercepts every link click and opens the destination inside an isolated, containerised browser session.

The user browses the destination entirely within the secure container. Threats that execute on the page exploits, downloads, scripts are contained within that session and discarded when it ends.

Before opening any link, CyberCheck360 runs a multi-layer check:

1. Blacklist Check

The destination URL and its domain are checked against global threat intelligence blacklists. Known malicious URLs and domains are flagged immediately.

2. Domain Age Analysis

Newly registered domains are a major indicator of phishing and fraud infrastructure. CyberCheck360 surfaces the domain registration date and domain age so users and administrators can make an informed decision before opening the link.

3. Organizational Blacklists and Allow Lists

Every organization has its own risk profile. CyberCheck360 allows administrators to define:

  • Organizational Blacklists - domains or URLs that are always blocked for all users
  • Organizational Allow Lists - trusted domains or URLs that users are permitted to open in their local browser

This gives security teams granular control over what their users can and cannot access, independent of global threat databases.


When a user clicks a link inside an email whether from the CyberCheck360 extension, Gmail add-on, or email admin portal the following happens:

  1. The link is intercepted before it reaches the local browser
  2. Real-time checks are run blacklist, domain age, organizational policies
  3. The user is presented with the Advanced Link Isolation screen, showing:
    • The destination URL
    • Domain registration date and domain age
    • Two options to proceed:

The link opens inside CyberCheck360's isolated, containerised browser. The user can view and interact with the page safely. Any threats that execute are contained and discarded after the session. The local device and network are never exposed.

Option B: Open in Local Browser

If the user recognises and trusts the link, they can choose to open it in their local browser. This option is available but not recommended by default it is intended for links the user is confident are safe.

CyberCheck360 URL Sandbox isolation screen giving users the option to open any link in a secure isolated browser keeping threats contained away from the local device. Only trusted links from the organization is allowed to open locally


Raising a Local Browsing Request

In some cases, a user may need to open a link in their local browser for legitimate reasons for example, to access an internal tool, a web application that requires a local session, or a trusted vendor portal.

If the link is not yet on the organizational allow list, the user can raise a local browsing request directly from the Advanced Link Isolation screen.

"If you trust this sender, kindly raise a request for local browsing."

How It Works

  1. The user clicks "raise a request for local browsing" on the isolation screen
  2. The request is sent to the organization's security administrator for review
  3. Once the administrator approves the request, the domain or URL is added to the organizational allow list
  4. The user can then open that link locally going forward

This ensures that local browser access is never unilaterally granted by the end user it always goes through an administrator approval process. Organizations maintain full visibility and control over what their users open locally.

CyberCheck360 URL Sandbox warning banner alerting users before opening any link with an option to raise a local browsing request if the link is not suspecious/malicous


CyberCheck360's secure link isolation implements a zero-trust approach to every URL clicked within your organization.

Under a zero-trust model, no link is trusted by default, regardless of the sender, the domain reputation, or how familiar the URL appears. Every link is verified and isolated before the user is exposed to it.

This approach protects against:

  • Time-of-click phishing attacks - links that appear clean at delivery but redirect to malicious content when clicked
  • Drive-by downloads - malware that executes automatically when a page loads
  • Click-by-download threats - files that download silently without user interaction
  • Local malware execution - scripts and exploits that run in the local browser environment
  • Credential harvesting pages - convincing fake login pages that steal usernames and passwords
  • Zero-day exploits - threats not yet on any blacklist

What This Means for Your Organization

Without CyberCheck360With CyberCheck360 Secure Link
Every link opens directly in the local browserEvery link is isolated before reaching the local browser
Blacklist checks only at delivery timeReal-time checks at the moment of click
No visibility into domain age or registrationDomain age and registration surfaced to the user
No organizational control over link accessAdmin-controlled allow lists and blacklists
Users decide unilaterally what to openLocal access requires administrator approval
Drive-by downloads reach the local deviceAll downloads contained within the isolated session

How to Access the URL Sandbox

CyberCheck360's URL sandbox is available across multiple entry points depending on how your team works.


1. Free Web Sandbox

Open any link in the sandbox directly from the CyberCheck360 website no account required.

Access: https://cybercheck360.com/url-sandbox/

Paste any URL and open it in an isolated browser session instantly. Ideal for one-off checks on suspicious links.

CyberCheck360 URL Sandbox tool where users can paste any link and open it in an isolated sandbox session for safe browsing


2. Threat Intelligence Platform (TIP)

CyberCheck360's Threat Intelligence Platform provides deep URL analysis alongside sandbox access.

Steps:

  1. Go to https://tip.cybercheck360.com/search/url-lookup
  2. Enter any URL in the IOC lookup search field
  3. Once results are returned, click "Go to Live Session"
  4. The URL opens inside a fully isolated sandbox session

CyberCheck360 Threat Intelligence Platform URL lookup results showing the Go to Live Session button to open a URL in an isolated sandbox


3. Email Security Portal

For organizations using email.cybercheck360.com, administrators and users can open any link or file from an email directly in the sandbox from within the admin portal.

Steps:

  1. Log in to your CyberCheck360 email security portal at email.cybercheck360.com
  2. Go to "Safe Browsing"
  3. Paste any Link to open a link in sandbox.
  4. Navigate to "File" Upload anyfile to open the file in a sandbox.

Note: Uploaded files are removed immediately after the sandbox session is destroyed. Not stored anywhere internally.

CyberCheck360 Email Security Portal showing admin and users opening links and files in an isolated sandbox session


4. CyberCheck360 Email Threat Defense — Microsoft Office 365 Add-on

The "CyberCheck360 Email Threat Defense" Outlook Add-on works directly inside your Outlook client and can analyse all emails and links in your mailbox.

Steps:

  1. Install the CyberCheck360 Email Threat Defense extension from your Microsoft marketplace
  2. Search "cybercheck360" in https://marketplace.microsoft.com/en-us/
  3. click "Get it Now" on the "Cybercheck360 Email Threat Defense" app.
  4. Once installed, you will be able to open the add-on from your toolbar and can analyse all emails and links using the add-on.
  5. Click "Open Sandbox" next to any link to open it in an isolated session

CyberCheck360 Outlook Add-On highlighting the Open Sandbox button to safely isolate and inspect email links


5. Gmail Add-On

The CyberCheck360 Gmail add-on integrates directly into Gmail and works the same way as the browser extension.

Steps:

  1. Install the CyberCheck360 add-on from the Google Workspace Marketplace
  2. Open any email in Gmail
  3. The add-on panel shows all links found in the email with their status (Benign, Unsafe, Unknown)
  4. Click "Sandbox" next to any link to open it in an isolated session

CyberCheck360 Gmail Add-On showing email links with Sandbox option for secure link isolation


Threats Stopped by URL Sandboxing

CyberCheck360's URL sandboxing and secure link isolation protects your organization from a wide range of email-borne threats:

  • Phishing attacks - credential theft pages are opened in isolation, not in the local browser
  • Ransomware delivery via links - payloads are triggered inside the container, not on the device
  • Drive-by downloads - files that auto-download on page load are contained within the session
  • Click-by-download malware - silent downloads never reach the local file system
  • Zero-day browser exploits - even unknown vulnerabilities cannot escape the isolated container
  • Time-of-click redirects - links that change destination after delivery are still intercepted at click time
  • Malvertising - malicious ads served on otherwise legitimate pages are isolated
  • Tracking and fingerprinting scripts - user identity and device information are not exposed

Get Started

CyberCheck360's URL sandbox is free to try, no account required.

For enterprise deployments, email security integration, or to learn more about CyberCheck360 Secure Link for your organization, visit cybercheck360.com.


Tags: URL Sandboxing, Email Security, Link Isolation, Phishing Protection, Zero Trust, Secure Browsing, CyberCheck360, Click-Time Protection, Browser Isolation, Threat Intelligence