Blocking Malicious URLs in SMS - ONP v/s SMS Phishing Protection

The following table compares how SMS Phishing Protection and ONP features block malicious URLs in SMS on iOS and Android platforms.

Feature iOS Android
SMS Phishing Protection
  1. The feature can be enabled only by the mobile user (due to iOS policy). To enable, see Preventing SMS Phishing.

  2. SMS from known contacts are not inspected.

  3. Only URLs in SMS are inspected (context is not inspected for privacy reasons)

  4. Malicious SMSes are silently quarantined to Junk inbox.

  5. Admins or end-users are not updated about this due to Apple privacy policy.

  1. The feature must be enabled by the administrator in the Mobile Security Administrator Portal and the mobile user needs to grant the SMS permission to Mobile Security.

  2. Only URLs in SMS are inspected.

  3. The administrator and the end-user are notified when a malicious URL is detected.

  4. User needs to manually remove the SMS from the device as Mobile Security does not have the permission to remove SMS.

  5. A risk level is raised for the device until the user deletes the malicious SMS.

No user action is required to detect malicious links with SMS Phishing Protection (users do not need to open the SMS and tap the link).
ONP
  1. Feature is enabled by the administrator in the Mobile Security Administrator Portal or by the UEM.

  2. End-user accesses the SMS with malicious link.

  3. When user taps the link, access is blocked.

  4. User is redirected to blocking page.

  5. Administrator is notified about the access attempt.

    Administrator can also add the URL to the URL Filter Categories.

ONP protects users from malicious URLs from different sources (SMS, Email, WhatsApp). However, to detect the malicious link with ONP, the user need to open the SMS/message source and tap the link.

To ensure complete protection from malicious URLs in SMS, Check Point recommends to enable both ONP and SMS Phishing Protection.