Forward it.
Search it.
Verify it.
The email that costs you money looks exactly like the one that doesn't. A fake invoice doesn't look fake. That's the problem. Fraud doesn't arrive looking like fraud. It looks like business as usual. The most dangerous email in your inbox looks completely ordinary.
Sender Registry is a business email intelligence network. Forward a suspicious email and get a real, evidence-based assessment back. Free, in minutes. Search the registry for a sender, domain or campaign. Verify an important request before your business acts on it.
Forward any suspicious email to this address.
No account needed.
Ask the network: has anyone seen this?
Search a sender, domain, subject line or campaign. Sender Registry checks what the network has seen before, related campaigns, risk history and connected infrastructure. It shows its full record, not just a single verdict.
A sender we've never seen before is never automatically marked safe. Human beings have already invented enough ways to abuse a green tick.
Verify before your business acts.
Changed bank details. An "urgent" payment request. A supposed supplier instruction. Sender Registry runs a focused check for supplier impersonation, lookalike domains, unusual sender relationships and campaign history. Because the time to spot invoice fraud is before the money moves, not after.
Try it yourself.
Search a domain below and see the kind of record Sender Registry keeps. A live example, not your own data.
Seen in 4 reports across 3 independent organisations. First seen 11 days ago, last seen yesterday. Impersonates a document-signing review request.
Sign in to see the full record →Registered 6 days ago. No confirmed reports against it yet, but its structure closely matches a known delivery-notification lookalike pattern - exactly the kind of early signal that report history alone would miss.
Sign in to see the full record →No suspicious reports against this domain in the network. That's not the same as a guarantee of safety. It means the network hasn't seen anything concerning yet. Sender Registry never marks an unseen sender as "safe."
What Sender Registry investigates.
Every forwarded email is broken down into real evidence, not a black-box score.
See the full capability tour →Beyond one email. Understand the operation.
A single suspicious email may look isolated. Across a network, it's often the first visible part of a much larger campaign.
Recurring monitoring, not a one-off check.
Supplier Watch monitors the businesses you trust. Executive Watch looks for external emails impersonating your directors and finance staff. Brand Watch tells you when someone is pretending to be your company. Domain Lookalike Radar watches for confusingly similar domains, before anyone's been phished with them.
My Exposure shows campaigns and threats connected to your organisation specifically. Not generic threat news. Threats Like Yours highlights activity being reported by similar businesses right now.
Watch an attack unfold, then see the whole family.
99% fingerprint match to a separately-named campaign. Same infrastructure, same templates, different domain.
While you were away, 3 campaigns relevant to your business emerged.
→ 3 active campaigns, 1 ELEVATED
→ 201 Created · SR-822104 queued
Is someone forging your own domain right now? Most businesses have no way to know.
Every other part of Sender Registry protects you from threats arriving at your business. Domain Health checks the other direction: can somebody use your domain to attack somebody else? A missing or weak DMARC policy means anyone can send email that looks like it's from you, with nothing stopping it.
We grade your domains from A to F, checking SPF, DKIM, DMARC and more automatically. We explain what is actually wrong in plain English, and give you the exact DNS record to add to fix it, with your own details already filled in.
Value: v=DMARC1; p=none; rua=mailto:you@yourcompany.com
Getting cryptic DMARC reports you cannot read? We turn them into plain English.
Once you set up DMARC, providers like Google start emailing you daily reports as compressed XML files. They are written for machines, so most people open the ZIP, see a wall of tags and IP addresses, and give up. Buried in there is genuinely useful information: who has been sending mail as your domain, and whether anyone is trying to spoof you.
Upload one and we read it for you. You get a plain-English verdict, the real services sending as your domain (Google, Microsoft 365, Resend and more, named for you), whether SPF, DKIM and DMARC passed, an A to F grade for your domain's own setup, a flag on any sender our network already knows to be bad, and whether anything needs your attention. Free, no account needed, and we never store your file.
Want it watched for you? On a paid plan we ingest your DMARC reports automatically, keep a running history of who is sending as your domain, and alert you the moment a new sending source appears or your authentication rate drops. Correlated and Verified add your registered suppliers' and brands' domains too.
You can hover a link and read the domain. You cannot safely go and see what is waiting.
Almost every email security tool examines the email. Is the sender genuine, does the wording look suspicious, is that link already on a list of known bad ones. All useful, and all the same thing: reading the letter and checking the postmark.
We follow the link and look at the page at the other end, inside our own systems rather than on your computer. If it asks for a password, we check two things. Would that password be sent off to a different website. Does the page title itself as a company it does not belong to. Either one, and you get a warning naming the actual site before you type anything.
It also works on an ordinary forward. Most forwarded emails lose their technical headers on the way, which blinds a lot of standard security checks before they even start. The links are always there.
We do not run the scripts on a page and we do not take pictures of it, so a sophisticated fake can still hide from us. Finding something is strong evidence. Finding nothing simply means we found nothing.
Everyone else reads the email. We go and look at where its links actually lead.
The fake of your brand, spotted before it’s ever used against you.
A convincing fake of your domain is often registered well before it sends its first email: a swapped letter, a hidden Cyrillic character identical to a Latin one, or an added word like secure or billing. By the time a fake invoice reaches an inbox, the fraud is already moving. Most protection only reacts once someone reports the fake.
For every brand domain you add to Business Watch, Sender Registry generates the lookalikes an attacker is most likely to register, and watches for any of them appearing. It also monitors public certificate transparency logs, where a new site’s security certificate is published, often before the site is even live. The moment a match is found, you learn whether it can already send email as you or serve a live page, so you know exactly how seriously to take it.
Stand out as a verified sender.
Verify your domain once and earn a verified badge for your website and email signature, plus your own public verified record. It is a credibility signal that gives visitors and clients extra confidence they are dealing with the genuine you, not a lookalike.
When someone forwards one of your emails to Sender Registry to check it, we tell them whether it genuinely came from your verified domain. If anyone starts using your name to impersonate that domain, you learn about it straight away. Verifying is optional and takes a couple of minutes, and not being verified is never held against you.
FOR VERIFIED SENDERS
Give your customers somewhere to ask.
Your customers already get emails pretending to be you. Most of them have nobody to ask, so they either pay a fraudster or they stop trusting your real mail. Both cost you.
A verified brand gets a checking address to hand out. Your customer forwards anything that claims to be from you, gets a plain-English answer in minutes and needs no account. You see the impersonation attempts made against you, reported by the people it was aimed at.
You also see something no other tool can tell you: which of your own genuine emails customers do not trust. If your renewal notice gets checked forty times, that is a design problem worth fixing.
On Correlated and Verified, our two higher plans, publish verify@yourdomain.com
instead of ours. Sender Registry never needs access to your email.
Acme: the email you asked us to check
About the email you forwarded to Acme
This claims to be Acme. The real Acme is a verified sender and only sends from acme.example: acme-invoices.example is not one of their domains. Treat it as an impersonation attempt.
This check was carried out by Sender Registry on behalf of Acme.
Not every fraudulent email is fake. Sometimes it really is them.
The most damaging invoice fraud does not come from a lookalike address. It comes from a supplier you have trusted for years, whose real email account has quietly been taken over. The message is genuine, sent from their genuine address, which is exactly why it works and why an ordinary phishing check waves it through.
When several organisations start reporting fraud from a domain one of them has registered as a trusted supplier, Sender Registry recognises the pattern and warns you the account may be compromised, so you verify by phone before paying anything. We never blocklist a compromised legitimate domain, because it will be cleaned up and back to normal.
The email can be perfect. The bank account can still be a criminal's.
Every scam that asks for money has a money target: a bank account, a crypto wallet, a phone or callback number, a payment handle. The same account turns up in scam after scam, often a mule account moving stolen funds. A check that only reads the wording of an email never sees it.
Sender Registry reads those payees out of every scam email the network sees and remembers the ones confirmed as fraud. When one turns up again, your assessment carries a clear warning: do not pay it. It is shown on every account, including free ones, because somebody about to send money to a criminal should be told.
Have the account but not the email? The free Check a Payee tool lets you paste a bank account, wallet, number, or handle and find out in seconds. Nothing you check is stored: it is turned into a one-way fingerprint, matched, then discarded.
Check a payee, free →Is this spam, or is it dangerous? Those are two different questions.
A newsletter you are tired of and an invoice-fraud attempt are both "unwanted email", and that is where the similarity ends. Most tools collapse them into one score, so a harmless mailing list and a genuine attack end up sitting next to each other looking roughly the same.
Sender Registry answers both, separately. Every email you forward still gets its danger verdict exactly as before. Alongside it, we now say what kind of mail it was: a real person writing to you, a receipt you expected, bulk marketing, cold sales outreach, or junk. Being bulk never raises the risk score, because bulk is not an accusation.
Then we ask you one question: did you want it? That answer is the part no classifier can guess, because only you know what you signed up for. When enough separate organisations tell us the same thing about a sender, that sender becomes a known bulk source across the whole network, and we show the working: how many organisations, and what share of them said so.
Where it is safe to do so, we can unsubscribe you. Where it is not, we say so and stop. An unsubscribe link on a dangerous email is not an unsubscribe link: it is confirmation that a real person read the message.
Spring collection: 30% off everything
news@fashion-updates.example
What kind of mail
Bulk marketing
Sent to many recipients. Annoying perhaps, but a normal mailing list. This does not affect the risk score.
Did you want this email?
Known bulk source
4 independent organisations told us they did not want mail from this sender, out of 5 who answered (80%).
The network keeps working after you've stopped looking.
An assessment isn't a one-time verdict. If new reports later reveal that an earlier email was part of an attack, Sender Registry reaches back and tells you.
Not enough network evidence yet to be certain either way. Not the same as "safe."
Two other organisations independently reported the same sender. Your earlier assessment is linked, and you're alerted automatically.
Built on evidence, not a verdict you have to trust blindly.
Risk, Confidence, Network Confirmation: always separate
Never collapsed into one traffic-light score. You see how dangerous something looks, how certain we are, and how much of the network has corroborated it. Three different questions.
"Not previously seen" is never "safe"
An absence of network history means the network hasn't built enough intelligence yet. Not that something has been cleared. We say so explicitly, every time.
Every claim shows its working
Timestamps, first seen, last seen, evidence freshness, and a plain-English reason for every contribution to a score. Expandable, never hidden behind the number.
Start free. Upgrade when you need the network.
No hidden tiers, no "contact sales" wall on the basics.
Free
Forward an email, get a real answer.
- Forward suspicious emails for a free assessment
- Risk, Confidence & Recommended Action
- Fake sign-in page detection
- Spam & mail type: is this junk, or is it dangerous?
- Block This Sender instructions
- Report confirmed threats to national authorities
- Your domain security grade (A to F)
- Verified sender badge & public record
- 1 seat
Observed
For a small business ready to search the network.
- Everything in Free
- Registry Search & full Registry Records
- Continuous DMARC monitoring for your domain
- A checking address for your own customers
- Safe unsubscribe from genuine bulk mail
- Cases & Investigations, Verify Before You Act
- Campaigns, Replay, Threat DNA, Intelligence Map
- Alerts & priority support
- 2 seats
Correlated
For a growing business that wants to get ahead of threats.
- Everything in Observed
- Business Watch: Supplier, Executive, Brand, Lookalike
- Supplier & brand domain grades, monitoring & alerts
- My Exposure & Threats Like Yours
- Briefings, PDF & CSV Reports
- 4 seats
Verified
For MSPs and teams who need to integrate.
- Everything in Correlated
- Full Threat API: report submission, watch management
- Webhooks with automatic retry
- Higher rate limits
- 6 seats
For developers
Building an app? Stop fake signups before they happen.
The Signals API checks disposable emails, Tor IPs, risky domains and known-bad senders in a single call. Free to start, no card needed.
What to look out for.
Five signals worth checking for in any message that feels slightly off.
A claimed authority
Does the message claim to be your bank, a supplier, a government department, or someone senior in your own organisation?
Manufactured urgency
Are you being told to act "within 24 hours" or "immediately", or threatened with a consequence if you don’t?
An emotional pull
Does it make you anxious, hopeful, or curious enough to act before thinking it through?
Scarcity or an unusually good offer
Is it dangling something in short supply, or a deal that seems too good to check first?
A hook into current events
Does it reference something genuinely in the news, or a predictable seasonal moment such as a tax deadline, to seem timely and relevant?
Before you act: verify using a contact method you already know and trust, such as a number from a previous invoice, or the organisation's own website. Never a number or link provided in the suspicious message itself.
Save it before you need it.
Add our reporting address to your contacts now, so it's already there the next time a suspicious email lands in an inbox.
Scan with your phone's camera to save straight to your contacts.
Save to your contacts now, so it's already there next time you need it.
Add to Contacts
Or share this QR code with someone on another device.
Protection that follows you, not just your inbox.
Free on every plan. Works the same on iPhone and Android.
Alerts the moment it matters
The moment something urgent is spotted, it's flagged in your app — no need to keep checking your inbox.
Scan any QR code, anywhere
A suspicious QR on a letter or invoice? Scan it and get an instant verdict on where it really leads.
Share it straight from anywhere
See a dodgy text or link? Share it into the app and get a clear verdict back in seconds.
Your Sender Registry, one tap away.
Add it to your home screen and open it like any other app. Full-screen, no app store, installing in seconds.
Forward your first email. Free, in minutes.
No account. No card. Get a real, evidence-based assessment back, and see what the network already knows about the sender.
Forward any suspicious email to this address. No account needed.