FOR VERIFIED SENDERS
Your customer cannot tell. The invoice looks like yours. The signature looks like yours. The bank details are not.
Give them somewhere to ask. They forward anything that claims to be from you and get an answer in minutes. You find out every time it happens.
Acme: the email you asked us to check
About the email you forwarded to Acme
This claims to be Acme. The real Acme is a verified sender and only sends from acme.example: acme-invoices.example is not one of their domains. Treat it as an impersonation attempt.
This check was carried out by Sender Registry on behalf of Acme.
When a fake lands in your customer's inbox, one of two things happens. Both cost you.
They pay it.
You find out weeks later, when the real invoice is chased. The money is gone. The relationship is damaged. The conversation starts with your customer asking why nobody warned them.
They stop trusting you.
This is the expensive one. Nothing is reported. Nothing is chased. Your genuine mail starts going unanswered because it is no longer worth the risk of being wrong. You never hear about this at all.
Neither happens because your customer is careless. It happens because they had nobody to ask. A five-second question had no five-second answer.
Not every forward is a fake. Some of them are your own genuine mail. That is the most useful report you will get.
If your renewal notice gets checked forty times, nobody is attacking you. Your renewal notice looks like a scam. Forty customers hesitated before acting on it. That is a design problem worth fixing. It is costing you replies today and until now there was no way to find out.
Every other tool tells you about mail arriving at your business. This tells you how your mail lands when it leaves.
Three steps. Your customer does one of them.
STEP ONE
You publish an address.
Put it on your invoices, in your email signature, on your contact page. Use ours
or publish verify@yourdomain.com and forward it to us.
STEP TWO
Your customer forwards.
Anything that claims to be from you and does not feel right. No account, no signup, no app, nothing to explain to them beyond the address itself.
STEP THREE
Everybody gets an answer.
They get a plain-English verdict in minutes. You get the impersonation attempt, the domain behind it and the fact that a customer needed to check at all.
Most of them will not tell your customer whether the email was real.
PayPal, Barclays and the National Cyber Security Centre all publish an address for suspicious email. Forward one to any of them and it is collected, investigated and filed. What almost none of them does is tell the person who sent it whether the email was genuine, so your customer is still sitting there wondering whether to pay the invoice.
phishing@paypal.com
Collects it
internetsecurity@barclays.co.uk
Collects it
report@phishing.gov.uk
Collects it
verify@docusign.com
Replies in two hours
verify@yourdomain.com
Replies in minutes
DocuSign is the only one of them that replies at all. Yours replies in minutes, every time, without anyone at your business touching it.
You can use ours or your own. We give you a Sender Registry
email address that works the moment you publish it, with no mailbox to create,
no DNS to change and nothing to install. With Correlated and Verified, our two higher
plans, you can publish verify@yourdomain.com instead.
Your customer gets the answer they needed. You get the intelligence you could not have collected any other way, because it was never sent to you.
Every fake sent in your name goes to someone else's inbox. You are the last person to find out, usually only when it has already cost somebody money. A checking address turns the people being targeted into the people warning you.
On Correlated and above the reply carries your name alongside ours. You get two PDFs with your logo on them: an impersonation summary for a board pack and a customer protection summary for your own staff. Compare the plans.
The objection to any security tool is usually what it asks of the person on the other end. This one asks for nothing.
No account
Nothing to sign up for, nothing to remember, no password to reset.
Nothing to install
No app, no extension, no change to how they read their email.
No cost to them
They forward an email and get a reply. That is the whole interaction.
This page will be read by people evaluating a security product, so here is the honest shape of it.
It does not read your email.
We see what your customers choose to forward to the checking address, nothing else. A branded address is a forwarding rule inside your own mail system, so we never need access to your mailbox.
You do not see mail that is not about you.
If a customer forwards something that turns out to have nothing to do with your business, you are told a check happened and nothing more. Their email is not yours to read. We do not hand it to you.
It cannot stop the fake being sent.
Nothing can. What it does is tell your customer not to act on it and tell you it happened, while the campaign is still running rather than after the money has moved.
It only works if people know the address.
A checking address nobody has seen protects nobody. It belongs on your invoices and in your signature, in the same place you already tell customers you will never ask them to change bank details by email.
You only have to stop one. A single redirected invoice can cost more than a year of protecting every customer you have.
Verify your domain. Publish the address. Start seeing what is being sent in your name.
You can change this at any time.
Every object in the registry (a sender, a domain, a campaign) moves through five stages as independent evidence builds:
This is deliberately separate from Risk and Confidence. How much of the network agrees is a different question from how dangerous something looks, or how certain we are.
Every campaign gets scored across 8 axes: infrastructure, domain patterns, message templates, link behaviour, attachment patterns, target industries, target roles, and campaign velocity. All plotted as a fingerprint.
Sender Registry compares every campaign's fingerprint against every other campaign's using cosine similarity: the same technique used to compare documents by meaning, not just matching words. A high match (we only ever suggest one above 55% similarity) means two campaigns that look unrelated on the surface may share real infrastructure, even under completely different domain names.
Senders, domains, URLs, attachments, campaigns, brands and suppliers all become nodes in a shared relationship graph, built from real evidence: a sender using a domain, a domain appearing in the same report as another domain, a report belonging to a campaign.
On a phone, we deliberately don't force a giant graph onto a small screen. Instead you get a focused view: the object you're looking at, and everything directly connected to it, with a tap to move to any of those connections in turn.
Add Sender Registry to your home screen and turn on notifications from your account - both free, both take under a minute. From then on, anything urgent (a payment-diversion campaign, an executive impersonation attempt) reaches you as a real notification on your lock screen, the same way any other app alerts you.
Every notification is sent end-to-end encrypted directly to your device - nothing is readable in transit by anyone other than your phone.
Open Verify Before You Act, point your camera at a QR code, and capture it. The image is decoded and the destination it leads to is checked exactly the same way we already check a QR code found inside a forwarded email - the same detection, just with your camera as the front door.
You'll see whether the destination is safe, blocked, or worth a second look, with a plain explanation either way.
On Android, once the app is added to your home screen, "Sender Registry" simply appears as an option in your phone's normal Share menu - the same one you'd use to send a photo to a friend. Share a suspicious text or link straight in, review it, and submit.
On iPhone, Apple's own software doesn't allow a website to appear in the Share menu automatically. A short, one-time setup (a free "Shortcut") gets you the same result - after that one step, it behaves identically on both phones.