PhishingGuard watches an inbox and runs domain, link, header, attachment, and AI content checks on every message in parallel — then scores it LOW, MEDIUM, or HIGH risk and alerts your team before anyone clicks anything.
No one on your team has to eyeball a suspicious message and guess — the workflow does the checking and hands you a verdict.
Connected directly to the inbox it's watching — new mail is picked up automatically, no forwarding step for anyone to remember.
Domain age, URL reputation, SPF/DKIM headers, attachment sandboxing, and AI analysis of the message body all run in parallel against real threat-intelligence services.
Results are weighted into a single risk score, classified LOW, MEDIUM, or HIGH, sent as an alert, and logged for audit — no manual write-up after.
Three risk levels the workflow classifies — click to see how each one scores.
Sample scans for illustration — based on the workflow's real scoring bands.
Each check runs independently and contributes weighted points to a single risk score — no single signal has to be conclusive on its own.
Looks up when the sender's domain was registered via WhoisXML API — domains under 30 days old are flagged, a common sign of a freshly spun-up phishing site.
Every link in the message is checked against VirusTotal and URLScan.io for known malicious content before anyone gets the chance to click it.
Validates SPF and DKIM signatures and checks for a Reply-To or Return-Path that doesn't match the visible sender — a classic spoofing tell.
Any attachment is submitted to Hybrid Analysis for dynamic malware evaluation instead of being trusted on file type alone.
Reads the message body itself for social-engineering tactics — urgency, credential requests, impersonation — the patterns a human would eventually notice, but faster.
All five checks feed a single weighted score, classified LOW (0–30), MEDIUM (31–60), or HIGH (61+) — alerted immediately and logged to a sheet for audit.
Built and running — every email that hits the connected inbox is checked against real threat-intelligence services (VirusTotal, URLScan.io, WhoisXML, Hybrid Analysis) and OpenAI, not a canned demo.
Pilot pricing shown below — final rates are confirmed with each customer during onboarding.
One inbox, essential checks
For teams & multiple monitored inboxes
Multiple teams or compliance requirements
Prices are early/pilot pricing and may change as we finalize plans with our first customers. PhishingGuard is intended for inboxes you own or are explicitly authorized to monitor.
We'll connect it to an inbox you own or manage and show you a real scan — the same five checks and scoring already running today.
Book a Demo