What matters gets lost between marketing and fraud

Try thisSwitch a rule off on the left and watch the inbox rearrange itself.

I want this
Mail for Komenza s.r.o.
3 mailboxes · 5 aliases · the rules are yours

Addresses

Rulestry switching off

Watched addresses4/4

  • Needs youtoday4
  • Fraud — quarantinednot delivered2
  • Can waitno deadline2
  • Bulk and marketingdigest only3
Fraud — quarantineducetni@vltava-dodavatel.example

Bank details changed for invoice 2026-0418

Hello, from this month please send payments to our new account…

Account on the invoice vs. in the e-mail

On invoice 2026-0418CZ12 3456 7890 1234 5678 9012
In this messageCZ88 2010 0000 0029 0114 7733

Why it is here

  • Account number changeddiffers from the last 6 invoicesSame supplier, same invoice, different account. This is the costliest fraud small companies meet — the right amount goes to the wrong account.
  • Not the domain you correspond withvltava-dodavatel.exampleYou have corresponded with this supplier from vltava.example for a year. This domain was registered three days ago.
  • Outside the threadnew message, not a replyThe message poses as a continuation but does not reply to any existing thread.

Held in quarantine

The message was not delivered. Accounting got an alert with both account numbers side by side and the supplier’s phone number from your records — not from the e-mail.

Illustrative demo. Names, companies and domains (.example) are invented and the links lead nowhere.

Plus and minus zoom, zero shows the whole demo, arrows move the zoomed demo.
  • 3 + 5mailboxes and aliases in one list
  • 4rules you switch yourself
  • 11messages in the demo inbox

The demo runs on made-up data. Figures describe the demo set-up, not client results.

I want this
What it solves

Several addresses and aliases in one inbox, sorted by what needs you today

Mail that sorts itself — by your rules, not a vendor’s.

Outlook and the rest give every company the same inbox and the same rules. This is the other option: your own mail, several mailboxes and aliases in one list, and an analyser that decides what needs you today, what can wait, and what is fraud. Switch a rule off in the demo and watch the inbox rearrange itself — that is the point. Turn them all off and you get the undifferentiated pile you already know.

Who it is forCompanies with several addresses and shared mailboxes

Delivered as part ofCybersecurity

What your staff get

Opens mail and sees three things that need answering today instead of forty that might.

Company owner

Shared addresses stop being a black hole: it is visible which alias a message came to, and every verdict carries its reasoning.

How it worksStep by step

  1. The message arrives

    It looks ordinary. Looking ordinary is exactly why someone opens it — the whole attack rests on that.

  2. Checking the sender

    Domain age, SPF and DKIM, whether the display name matches the address, reply-to pointing elsewhere than From.

  3. The link against its target

    Link text and real address side by side. A lookalike character in the domain is only visible once compared.

  4. A verdict with consequences

    Not a score but what happens: deliver, quarantine, block. And for the ambiguous one, honestly, "needs review".

  5. The loop back

    Reported messages and quarantine decisions return as signal. A filter without this loop ages.

What it doesWhat it needs in production

  • Signals, not a single number

    Domain age, display-name mismatch, reply-to divergence, link text versus target, urgency language, attachment type — each shown separately.

  • Lookalike domain detection

    Characters that render almost identically are the whole trick. The comparison is shown side by side rather than described.

  • Three outcomes, not two

    Deliver, quarantine for review, block. Forcing every ambiguous message into one of two buckets is how trust in the filter dies.

  • A report button that does something

    What people report becomes a signal. Without the loop back, awareness training is a yearly ritual with no effect.

  • A record for the incident report

    The analysis is kept with the message, so reporting an incident does not start with reconstructing what happened.

Who it is forWhere it makes sense

  • Small and mid-sized companies

    No security team, one shared mailbox, and an invoice-payment request that looks plausible enough.

  • Municipalities

    Public e-mail addresses, published names and roles — everything an attacker needs to write a convincing message.

  • Healthcare

    Staff who open attachments because an attachment is usually a genuine referral or report.

  • Anyone under NIS2

    Where incidents have to be reported, the reasoning behind a verdict is part of the record, not a nicety.

IntegrationsRuns on what you already have

  • Microsoft 365 / Exchange
  • Google Workspace
  • SPF / DKIM / DMARC
  • Entra ID
  • SIEM
  • Ticketing / helpdesk
  • Threat intel feeds
  • Quarantine console
  • Awareness training
  • REST API

The list is not exhaustive. We connect systems that are not here as long as they have an interface.

Want this in your business?

A no-obligation call with someone who builds these. We go through your brief and say what is realistic and what is not.

Book a consultation