Free to forward. No signup required.

Forward it.
Search it.
Verify it.

The email that costs you money looks exactly like the one that doesn't. A fake invoice doesn't look fake. That's the problem. Fraud doesn't arrive looking like fraud. It looks like business as usual. The most dangerous email in your inbox looks completely ordinary.

Sender Registry is a business email intelligence network. Forward a suspicious email and get a real, evidence-based assessment back. Free, in minutes. Search the registry for a sender, domain or campaign. Verify an important request before your business acts on it.

Forward any suspicious email to this address.
No account needed.

Just want to check one email? →

9:41
Sender Registry LITE
JB
HIGH
78/100
Risk
94%
Confidence
What to do
Verify before you act — the reply address and sending domain don't match the brand this claims to be.
Reply-To domain differs from From
Sender domain registered 3 weeks ago
Seen across the network
Assessments
Check
Account
THE NETWORK ADVANTAGE

One person spots it.
The whole network remembers it.

Every email reported here makes the whole network smarter. One person’s catch helps protect everyone who uses it. A free email checker looks at one message in isolation.

Sender Registry checks it against everything the network has already learned.

9:41
Sender Registry LITE
JB
Your assessments
Tap any card to read the full verdict
CRITICAL 20 Aug
Renewal #941164208 — Account Not Verified
Fake sign-in page impersonating Microsoft.
OBSERVED SR-847291 ›
CAUTION yesterday
Booking confirmation — flu jab
Newly-observed sender; treat with caution.
UNSEEN SR-861197 ›
Assessments
Check
Account

Ask the network: has anyone seen this?

Search a sender, domain, subject line or campaign. Sender Registry checks what the network has seen before, related campaigns, risk history and connected infrastructure. It shows its full record, not just a single verdict.

A sender we've never seen before is never automatically marked safe. Human beings have already invented enough ways to abuse a green tick.

Payment diversion

Verify before your business acts.

Changed bank details. An "urgent" payment request. A supposed supplier instruction. Sender Registry runs a focused check for supplier impersonation, lookalike domains, unusual sender relationships and campaign history. Because the time to spot invoice fraud is before the money moves, not after.

VERIFY BEFORE YOU ACT
Changed bank details detected. This request doesn't match your supplier's known domain.
Claims to beAshcombe & Reeve Supplies
Genuine supplier domainashcombe-reeve.co.uk
Sending domainashcombe-reeve-accounts.com
Domain similarity91% lookalike match
Recommended: verify by phone using a number from a previous invoice. Never one supplied in this message.

Try it yourself.

Search a domain below and see the kind of record Sender Registry keeps. A live example, not your own data.

Pick an example domain below…
Check your own domain, sender or link →

What Sender Registry investigates.

Every forwarded email is broken down into real evidence, not a black-box score.

See the full capability tour →
Sender identity
Authentication (SPF/DKIM/DMARC)
Domains
URLs and redirect chains
QR code destinations
Attachments
Disposable and throwaway senders
Campaign relationships
Network report history
Supplier relationships
Compromised senders
Fraud payees (bank accounts, wallets, numbers)
Message templates

Beyond one email. Understand the operation.

A single suspicious email may look isolated. Across a network, it's often the first visible part of a much larger campaign.

BUSINESS WATCH
Supplier Watch · 6 domains Active
Executive Watch · 4 people Active
Brand Watch · impersonation found 1 match
Lookalike Radar · 9 domains watched Active

Recurring monitoring, not a one-off check.

Supplier Watch monitors the businesses you trust. Executive Watch looks for external emails impersonating your directors and finance staff. Brand Watch tells you when someone is pretending to be your company. Domain Lookalike Radar watches for confusingly similar domains, before anyone's been phished with them.

My Exposure shows campaigns and threats connected to your organisation specifically. Not generic threat news. Threats Like Yours highlights activity being reported by similar businesses right now.

Watch an attack unfold, then see the whole family.

CAMPAIGN REPLAY
18 days ago
First seen: Manchester
12 days ago
Second organisation reports it
6 days ago
Report pace increases sharply
Yesterday
Reaches London; Retail added as a target
THREAT DNA
This campaign Matched campaign

99% fingerprint match to a separately-named campaign. Same infrastructure, same templates, different domain.

MONDAY MORNING BRIEFING

While you were away, 3 campaigns relevant to your business emerged.

· A payment-diversion campaign targeting Property, now ELEVATED
· Your Executive Watch caught an impersonation attempt
· Staff reported 6 suspicious emails; 2 confirmed threats
DEVELOPER / API
GET /api/v1/campaigns?industry=property
→ 3 active campaigns, 1 ELEVATED
POST /api/v1/reports
→ 201 Created · SR-822104 queued
sk_live_••••4f2a 1,204 calls · 30d 5,000/hr limit
Full registry & exposure access, report submission, watch management, and webhooks with automatic retry on failed deliveries.
Domain Health

Is someone forging your own domain right now? Most businesses have no way to know.

Every other part of Sender Registry protects you from threats arriving at your business. Domain Health checks the other direction: can somebody use your domain to attack somebody else? A missing or weak DMARC policy means anyone can send email that looks like it's from you, with nothing stopping it.

We grade your domains from A to F, checking SPF, DKIM, DMARC and more automatically. We explain what is actually wrong in plain English, and give you the exact DNS record to add to fix it, with your own details already filled in.

DOMAIN HEALTH · mail.yourcompany.com
SPF Found
DMARC Missing
HOW TO FIX THIS
Host: _dmarc.yourcompany.com
Value: v=DMARC1; p=none; rua=mailto:you@yourcompany.com
DMARC REPORT · yourcompany.com
Verdict Healthy
Messages analysed 1,240
Passed DMARC 100%
Google Workspace Authenticated
Email Security Analyser

Getting cryptic DMARC reports you cannot read? We turn them into plain English.

Once you set up DMARC, providers like Google start emailing you daily reports as compressed XML files. They are written for machines, so most people open the ZIP, see a wall of tags and IP addresses, and give up. Buried in there is genuinely useful information: who has been sending mail as your domain, and whether anyone is trying to spoof you.

Upload one and we read it for you. You get a plain-English verdict, the real services sending as your domain (Google, Microsoft 365, Resend and more, named for you), whether SPF, DKIM and DMARC passed, an A to F grade for your domain's own setup, a flag on any sender our network already knows to be bad, and whether anything needs your attention. Free, no account needed, and we never store your file.

Want it watched for you? On a paid plan we ingest your DMARC reports automatically, keep a running history of who is sending as your domain, and alert you the moment a new sending source appears or your authentication rate drops. Correlated and Verified add your registered suppliers' and brands' domains too.

Link Destination

You can hover a link and read the domain. You cannot safely go and see what is waiting.

Almost every email security tool examines the email. Is the sender genuine, does the wording look suspicious, is that link already on a list of known bad ones. All useful, and all the same thing: reading the letter and checking the postmark.

We follow the link and look at the page at the other end, inside our own systems rather than on your computer. If it asks for a password, we check two things. Would that password be sent off to a different website. Does the page title itself as a company it does not belong to. Either one, and you get a warning naming the actual site before you type anything.

It also works on an ordinary forward. Most forwarded emails lose their technical headers on the way, which blinds a lot of standard security checks before they even start. The links are always there.

We do not run the scripts on a page and we do not take pictures of it, so a sophisticated fake can still hide from us. Finding something is strong evidence. Finding nothing simply means we found nothing.

Everyone else reads the email. We go and look at where its links actually lead.

ASSESSMENT · SR-418302
⚠ A LINK LEADS TO A FAKE SIGN-IN PAGE
A link in this email leads to a page asking for a password that presents itself as Microsoft. That page is not on a Microsoft website.
WHERE THE LINK ACTUALLY GOES
ms-verify-account.top/signin
Page claims to be Microsoft
Impersonation Radar

The fake of your brand, spotted before it’s ever used against you.

A convincing fake of your domain is often registered well before it sends its first email: a swapped letter, a hidden Cyrillic character identical to a Latin one, or an added word like secure or billing. By the time a fake invoice reaches an inbox, the fraud is already moving. Most protection only reacts once someone reports the fake.

For every brand domain you add to Business Watch, Sender Registry generates the lookalikes an attacker is most likely to register, and watches for any of them appearing. It also monitors public certificate transparency logs, where a new site’s security certificate is published, often before the site is even live. The moment a match is found, you learn whether it can already send email as you or serve a live page, so you know exactly how seriously to take it.

IMPERSONATION RADAR · brand watch
⚠ NEW LOOKALIKE DETECTED Armed
yourcornpany.com was registered 3 hours ago. It mimics yourcompany.com and can already send email as you. Warn your team before it does.
Also watching: yоurcompany.com (hidden Cyrillic) · yourcompany-billing.com
Verified Sender

Stand out as a verified sender.

Verify your domain once and earn a verified badge for your website and email signature, plus your own public verified record. It is a credibility signal that gives visitors and clients extra confidence they are dealing with the genuine you, not a lookalike.

When someone forwards one of your emails to Sender Registry to check it, we tell them whether it genuinely came from your verified domain. If anyone starts using your name to impersonate that domain, you learn about it straight away. Verifying is optional and takes a couple of minutes, and not being verified is never held against you.

VERIFIED SENDER · public record
✓ Verified sender Identity verified
Acme Ltd
Confirmed genuine. Anyone checking an email from acme.com is told it is really you.
Add the badge to your site: a visitor can click it to confirm you are the real Acme Ltd.

FOR VERIFIED SENDERS

Give your customers somewhere to ask.

Your customers already get emails pretending to be you. Most of them have nobody to ask, so they either pay a fraudster or they stop trusting your real mail. Both cost you.

A verified brand gets a checking address to hand out. Your customer forwards anything that claims to be from you, gets a plain-English answer in minutes and needs no account. You see the impersonation attempts made against you, reported by the people it was aimed at.

You also see something no other tool can tell you: which of your own genuine emails customers do not trust. If your renewal notice gets checked forty times, that is a design problem worth fixing.

On Correlated and Verified, our two higher plans, publish verify@yourdomain.com instead of ours. Sender Registry never needs access to your email.

How it protects your business What your customers see

9:41
Inbox

Acme: the email you asked us to check

Sender Registry verify@mail.senderregistry.com 9:41

About the email you forwarded to Acme

RISK: CRITICAL Impersonating a verified brand

This claims to be Acme. The real Acme is a verified sender and only sends from acme.example: acme-invoices.example is not one of their domains. Treat it as an impersonation attempt.

What to do
Block this sender immediately
The full assessment, including what we checked

This check was carried out by Sender Registry on behalf of Acme.

ASSESSMENT · invoice update
⚠ THIS SENDER MAY BE COMPROMISED
accounts@yoursupplier.com is normally a legitimate sender, but several organisations have recently reported fraud from it. Verify any request by phone before acting, even if the email looks genuine.
Compromised suppliers

Not every fraudulent email is fake. Sometimes it really is them.

The most damaging invoice fraud does not come from a lookalike address. It comes from a supplier you have trusted for years, whose real email account has quietly been taken over. The message is genuine, sent from their genuine address, which is exactly why it works and why an ordinary phishing check waves it through.

When several organisations start reporting fraud from a domain one of them has registered as a trusted supplier, Sender Registry recognises the pattern and warns you the account may be compromised, so you verify by phone before paying anything. We never blocklist a compromised legitimate domain, because it will be cleaned up and back to normal.

Fraud payees

The email can be perfect. The bank account can still be a criminal's.

Every scam that asks for money has a money target: a bank account, a crypto wallet, a phone or callback number, a payment handle. The same account turns up in scam after scam, often a mule account moving stolen funds. A check that only reads the wording of an email never sees it.

Sender Registry reads those payees out of every scam email the network sees and remembers the ones confirmed as fraud. When one turns up again, your assessment carries a clear warning: do not pay it. It is shown on every account, including free ones, because somebody about to send money to a criminal should be told.

Have the account but not the email? The free Check a Payee tool lets you paste a bank account, wallet, number, or handle and find out in seconds. Nothing you check is stored: it is turned into a one-way fingerprint, matched, then discarded.

Check a payee, free →
ASSESSMENT · payment request
⚠ CONFIRMED FRAUD PAYEE · DO NOT PAY
GB29 **** **** 6819
This bank account has appeared in emails the network has confirmed as fraud. Verify the details with the supplier by phone, using a number you already trust, before paying anything.
Spam & mail type

Is this spam, or is it dangerous? Those are two different questions.

A newsletter you are tired of and an invoice-fraud attempt are both "unwanted email", and that is where the similarity ends. Most tools collapse them into one score, so a harmless mailing list and a genuine attack end up sitting next to each other looking roughly the same.

Sender Registry answers both, separately. Every email you forward still gets its danger verdict exactly as before. Alongside it, we now say what kind of mail it was: a real person writing to you, a receipt you expected, bulk marketing, cold sales outreach, or junk. Being bulk never raises the risk score, because bulk is not an accusation.

Then we ask you one question: did you want it? That answer is the part no classifier can guess, because only you know what you signed up for. When enough separate organisations tell us the same thing about a sender, that sender becomes a known bulk source across the whole network, and we show the working: how many organisations, and what share of them said so.

Where it is safe to do so, we can unsubscribe you. Where it is not, we say so and stop. An unsubscribe link on a dangerous email is not an unsubscribe link: it is confirmation that a real person read the message.

Assessment SR-418902 Low risk

Spring collection: 30% off everything

news@fashion-updates.example

What kind of mail

Bulk marketing

Sent to many recipients. Annoying perhaps, but a normal mailing list. This does not affect the risk score.

Did you want this email?

Yes, I wanted it No, I did not

Known bulk source

4 independent organisations told us they did not want mail from this sender, out of 5 who answered (80%).

Retrospective intelligence

The network keeps working after you've stopped looking.

An assessment isn't a one-time verdict. If new reports later reveal that an earlier email was part of an attack, Sender Registry reaches back and tells you.

09:12 · FIRST ASSESSED
LIMITED INTELLIGENCE

Not enough network evidence yet to be certain either way. Not the same as "safe."

17 minutes later
09:29 · RESOLVED
CRITICAL: campaign confirmed

Two other organisations independently reported the same sender. Your earlier assessment is linked, and you're alerted automatically.

Built on evidence, not a verdict you have to trust blindly.

Risk, Confidence, Network Confirmation: always separate

Never collapsed into one traffic-light score. You see how dangerous something looks, how certain we are, and how much of the network has corroborated it. Three different questions.

"Not previously seen" is never "safe"

An absence of network history means the network hasn't built enough intelligence yet. Not that something has been cleared. We say so explicitly, every time.

Every claim shows its working

Timestamps, first seen, last seen, evidence freshness, and a plain-English reason for every contribution to a score. Expandable, never hidden behind the number.

Read our full Methodology process Read a letter from our founder →

Start free. Upgrade when you need the network.

No hidden tiers, no "contact sales" wall on the basics.

Free

Forward an email, get a real answer.

Free
  • Forward suspicious emails for a free assessment
  • Risk, Confidence & Recommended Action
  • Fake sign-in page detection
  • Spam & mail type: is this junk, or is it dangerous?
  • Block This Sender instructions
  • Report confirmed threats to national authorities
  • Your domain security grade (A to F)
  • Verified sender badge & public record
  • 1 seat
Get started free

Observed

For a small business ready to search the network.

£35 /month
  • Everything in Free
  • Registry Search & full Registry Records
  • Continuous DMARC monitoring for your domain
  • A checking address for your own customers
  • Safe unsubscribe from genuine bulk mail
  • Cases & Investigations, Verify Before You Act
  • Campaigns, Replay, Threat DNA, Intelligence Map
  • Alerts & priority support
  • 2 seats
Get started
Most popular

Correlated

For a growing business that wants to get ahead of threats.

£65 /month
  • Everything in Observed
  • Business Watch: Supplier, Executive, Brand, Lookalike
  • Supplier & brand domain grades, monitoring & alerts
  • My Exposure & Threats Like Yours
  • Briefings, PDF & CSV Reports
  • 4 seats
Get started

Verified

For MSPs and teams who need to integrate.

£95 /month
  • Everything in Correlated
  • Full Threat API: report submission, watch management
  • Webhooks with automatic retry
  • Higher rate limits
  • 6 seats
Get started

For developers

Building an app? Stop fake signups before they happen.

The Signals API checks disposable emails, Tor IPs, risky domains and known-bad senders in a single call. Free to start, no card needed.

Explore the Signals API →
Compare plans Free Observed Correlated Verified
Forward & assess emails
Report to national reporting service
Mobile alerts, QR scanner & share sheet
Fake sign-in page detection
Spam & mail type
Fraud payee check
Your domain security grade (A to F)
Verified sender badge & public record
Continuous DMARC monitoring
Checking address for your customers
Verified domain impersonation alerts
Registry Search & full Registry Records
Verify Before You Act
Cases & Investigations
Campaigns, Replay, Threat DNA, Intelligence Map
Alerts
Safe unsubscribe
Priority support
Your own verify@ address & brand reports
Business Watch (Supplier/Executive/Brand/Lookalike)
Supplier & brand domain grades, monitoring & alerts
My Exposure & Threats Like Yours
Briefings (daily & weekly digests)
Slack & Microsoft Teams delivery
PDF Reports (Board, Insurance, Campaign)
CSV Data Export
Gateway Blocklist
Threat API & webhooks
Seats included 1 2 4 6

What to look out for.

Five signals worth checking for in any message that feels slightly off.

1

A claimed authority

Does the message claim to be your bank, a supplier, a government department, or someone senior in your own organisation?

2

Manufactured urgency

Are you being told to act "within 24 hours" or "immediately", or threatened with a consequence if you don’t?

3

An emotional pull

Does it make you anxious, hopeful, or curious enough to act before thinking it through?

4

Scarcity or an unusually good offer

Is it dangling something in short supply, or a deal that seems too good to check first?

5

A hook into current events

Does it reference something genuinely in the news, or a predictable seasonal moment such as a tax deadline, to seem timely and relevant?

Before you act: verify using a contact method you already know and trust, such as a number from a previous invoice, or the organisation's own website. Never a number or link provided in the suspicious message itself.

Read the full guidance →

Save it before you need it.

Add our reporting address to your contacts now, so it's already there the next time a suspicious email lands in an inbox.

QR code that adds Sender Registry's reporting address to your contacts

Scan with your phone's camera to save straight to your contacts.

Save to your contacts now, so it's already there next time you need it.

Add to Contacts QR code that adds Sender Registry's reporting address to your contacts

Or share this QR code with someone on another device.

Protection that follows you, not just your inbox.

Free on every plan. Works the same on iPhone and Android.

9:41
Sender Registry LITE
JB
Your assessments
The moment something's off, it's here
CRITICALnow
Payment diversion spotted
New bank details don't match your supplier.
OBSERVEDSR-847291 ›
CAUTION2h ago
Parcel redelivery — action needed
Newly-observed sender; treat with caution.
UNSEENSR-861905 ›
Assessments
Check
Account

Alerts the moment it matters

The moment something urgent is spotted, it's flagged in your app — no need to keep checking your inbox.

9:41
Sender Registry LITE
JB
SAFE
6/100
Risk
97%
Confidence
Destination checked
This QR code leads to a genuine site. Safe to continue.
ScannedQR code
Destinationsainsburys.co.uk
Assessments
Check
Account

Scan any QR code, anywhere

A suspicious QR on a letter or invoice? Scan it and get an instant verdict on where it really leads.

9:41
Sender Registry LITE
JB
HIGH
82/100
Risk
95%
Confidence
What to do
Don't tap this link — it isn't Royal Mail. Delete the message.
Shared linkroyalmail-redelivery-secure.co
ClassificationLikely phishing
Assessments
Check
Account

Share it straight from anywhere

See a dodgy text or link? Share it into the app and get a clear verdict back in seconds.

Your Sender Registry, one tap away.

Add it to your home screen and open it like any other app. Full-screen, no app store, installing in seconds.

Forward your first email. Free, in minutes.

No account. No card. Get a real, evidence-based assessment back, and see what the network already knows about the sender.

See plans

Forward any suspicious email to this address. No account needed.