Signature-based detection works by comparing incoming emails against a database of known signatures. When an email matches one of these signatures, it is flagged as potentially harmful. The system then takes predefined actions, which may include moving the email to a spam folder, blocking it entirely, or notifying the user. This method relies on the continuous updating of the signature database to include new threats as they are discovered.