What matters gets lost between marketing and fraud
Try thisSwitch a rule off on the left and watch the inbox rearrange itself.
Addresses
Rulestry switching off
Watched addresses4/4
- Needs youtoday4
- Fraud — quarantinednot delivered2
- Can waitno deadline2
- Bulk and marketingdigest only3
Bank details changed for invoice 2026-0418
Hello, from this month please send payments to our new account…
Account on the invoice vs. in the e-mail
Why it is here
- Account number changeddiffers from the last 6 invoicesSame supplier, same invoice, different account. This is the costliest fraud small companies meet — the right amount goes to the wrong account.
- Not the domain you correspond withvltava-dodavatel.exampleYou have corresponded with this supplier from vltava.example for a year. This domain was registered three days ago.
- Outside the threadnew message, not a replyThe message poses as a continuation but does not reply to any existing thread.
Held in quarantine
The message was not delivered. Accounting got an alert with both account numbers side by side and the supplier’s phone number from your records — not from the e-mail.
Illustrative demo. Names, companies and domains (.example) are invented and the links lead nowhere.
- 3 + 5mailboxes and aliases in one list
- 4rules you switch yourself
- 11messages in the demo inbox
The demo runs on made-up data. Figures describe the demo set-up, not client results.
I want thisSeveral addresses and aliases in one inbox, sorted by what needs you today
Mail that sorts itself — by your rules, not a vendor’s.
Outlook and the rest give every company the same inbox and the same rules. This is the other option: your own mail, several mailboxes and aliases in one list, and an analyser that decides what needs you today, what can wait, and what is fraud. Switch a rule off in the demo and watch the inbox rearrange itself — that is the point. Turn them all off and you get the undifferentiated pile you already know.
Who it is forCompanies with several addresses and shared mailboxes
Delivered as part ofCybersecurity
What your staff get
Opens mail and sees three things that need answering today instead of forty that might.
Company owner
Shared addresses stop being a black hole: it is visible which alias a message came to, and every verdict carries its reasoning.
How it worksStep by step
The message arrives
It looks ordinary. Looking ordinary is exactly why someone opens it — the whole attack rests on that.
Checking the sender
Domain age, SPF and DKIM, whether the display name matches the address, reply-to pointing elsewhere than From.
The link against its target
Link text and real address side by side. A lookalike character in the domain is only visible once compared.
A verdict with consequences
Not a score but what happens: deliver, quarantine, block. And for the ambiguous one, honestly, "needs review".
The loop back
Reported messages and quarantine decisions return as signal. A filter without this loop ages.
What it doesWhat it needs in production
Signals, not a single number
Domain age, display-name mismatch, reply-to divergence, link text versus target, urgency language, attachment type — each shown separately.
Lookalike domain detection
Characters that render almost identically are the whole trick. The comparison is shown side by side rather than described.
Three outcomes, not two
Deliver, quarantine for review, block. Forcing every ambiguous message into one of two buckets is how trust in the filter dies.
A report button that does something
What people report becomes a signal. Without the loop back, awareness training is a yearly ritual with no effect.
A record for the incident report
The analysis is kept with the message, so reporting an incident does not start with reconstructing what happened.
Who it is forWhere it makes sense
Small and mid-sized companies
No security team, one shared mailbox, and an invoice-payment request that looks plausible enough.
Municipalities
Public e-mail addresses, published names and roles — everything an attacker needs to write a convincing message.
Healthcare
Staff who open attachments because an attachment is usually a genuine referral or report.
Anyone under NIS2
Where incidents have to be reported, the reasoning behind a verdict is part of the record, not a nicety.
IntegrationsRuns on what you already have
- Microsoft 365 / Exchange
- Google Workspace
- SPF / DKIM / DMARC
- Entra ID
- SIEM
- Ticketing / helpdesk
- Threat intel feeds
- Quarantine console
- Awareness training
- REST API
The list is not exhaustive. We connect systems that are not here as long as they have an interface.
Want this in your business?
A no-obligation call with someone who builds these. We go through your brief and say what is realistic and what is not.
Book a consultation