FOR VERIFIED SENDERS

Criminals are emailing your customers using your name.

Your customer cannot tell. The invoice looks like yours. The signature looks like yours. The bank details are not.

Give them somewhere to ask. They forward anything that claims to be from you and get an answer in minutes. You find out every time it happens.

9:41
Inbox

Acme: the email you asked us to check

Sender Registry verify@mail.senderregistry.com 9:41

About the email you forwarded to Acme

RISK: CRITICAL Impersonating a verified brand

This claims to be Acme. The real Acme is a verified sender and only sends from acme.example: acme-invoices.example is not one of their domains. Treat it as an impersonation attempt.

What to do
Block this sender immediately
The full assessment, including what we checked

This check was carried out by Sender Registry on behalf of Acme.

The part you never hear about

When a fake lands in your customer's inbox, one of two things happens. Both cost you.

They pay it.

You find out weeks later, when the real invoice is chased. The money is gone. The relationship is damaged. The conversation starts with your customer asking why nobody warned them.

They stop trusting you.

This is the expensive one. Nothing is reported. Nothing is chased. Your genuine mail starts going unanswered because it is no longer worth the risk of being wrong. You never hear about this at all.

Neither happens because your customer is careless. It happens because they had nobody to ask. A five-second question had no five-second answer.

The thing no other tool can tell you

Not every forward is a fake. Some of them are your own genuine mail. That is the most useful report you will get.

If your renewal notice gets checked forty times, nobody is attacking you. Your renewal notice looks like a scam. Forty customers hesitated before acting on it. That is a design problem worth fixing. It is costing you replies today and until now there was no way to find out.

Every other tool tells you about mail arriving at your business. This tells you how your mail lands when it leaves.

How it works

Three steps. Your customer does one of them.

STEP ONE

You publish an address.

Put it on your invoices, in your email signature, on your contact page. Use ours or publish verify@yourdomain.com and forward it to us.

STEP TWO

Your customer forwards.

Anything that claims to be from you and does not feel right. No account, no signup, no app, nothing to explain to them beyond the address itself.

STEP THREE

Everybody gets an answer.

They get a plain-English verdict in minutes. You get the impersonation attempt, the domain behind it and the fact that a customer needed to check at all.

The biggest brands already do this

Most of them will not tell your customer whether the email was real.

PayPal, Barclays and the National Cyber Security Centre all publish an address for suspicious email. Forward one to any of them and it is collected, investigated and filed. What almost none of them does is tell the person who sent it whether the email was genuine, so your customer is still sitting there wondering whether to pay the invoice.

phishing@paypal.com Collects it
internetsecurity@barclays.co.uk Collects it
report@phishing.gov.uk Collects it
verify@docusign.com Replies in two hours
verify@yourdomain.com Replies in minutes

DocuSign is the only one of them that replies at all. Yours replies in minutes, every time, without anyone at your business touching it.

You can use ours or your own. We give you a Sender Registry email address that works the moment you publish it, with no mailbox to create, no DNS to change and nothing to install. With Correlated and Verified, our two higher plans, you can publish verify@yourdomain.com instead.

Both sides of the same email

Your customer gets the answer they needed. You get the intelligence you could not have collected any other way, because it was never sent to you.

Every fake sent in your name goes to someone else's inbox. You are the last person to find out, usually only when it has already cost somebody money. A checking address turns the people being targeted into the people warning you.

On Correlated and above the reply carries your name alongside ours. You get two PDFs with your logo on them: an impersonation summary for a board pack and a customer protection summary for your own staff. Compare the plans.

Inbox Your customer's mailbox
Acme Invoices 09:14
Invoice 4471, updated bank details
Please note our account has changed ahead of FAKE
Acme Billing Mon
Your annual renewal is due
Your cover runs to 14 September. To renew GENUINE
Acme Accounts Sun
Payment failed, update your card
We were unable to take payment. Confirm your FAKE
Acme Support Sat
Your account will be suspended
Action is required within 24 hours to avoid FAKE
Acme Fri
Statement for August attached
Please find your statement enclosed as a PDF FAKE
Four of these were never sent by Acme. The one that was got checked forty times.

It costs your customer nothing

The objection to any security tool is usually what it asks of the person on the other end. This one asks for nothing.

No account

Nothing to sign up for, nothing to remember, no password to reset.

Nothing to install

No app, no extension, no change to how they read their email.

No cost to them

They forward an email and get a reply. That is the whole interaction.

What it does not do

This page will be read by people evaluating a security product, so here is the honest shape of it.

It does not read your email.

We see what your customers choose to forward to the checking address, nothing else. A branded address is a forwarding rule inside your own mail system, so we never need access to your mailbox.

You do not see mail that is not about you.

If a customer forwards something that turns out to have nothing to do with your business, you are told a check happened and nothing more. Their email is not yours to read. We do not hand it to you.

It cannot stop the fake being sent.

Nothing can. What it does is tell your customer not to act on it and tell you it happened, while the campaign is still running rather than after the money has moved.

It only works if people know the address.

A checking address nobody has seen protects nobody. It belongs on your invoices and in your signature, in the same place you already tell customers you will never ask them to change bank details by email.

Give your customers somewhere to ask.

You only have to stop one. A single redirected invoice can cost more than a year of protecting every customer you have.

Verify your domain. Publish the address. Start seeing what is being sent in your name.