One address to report suspicious email.
Customers and staff forward it. Reporters whose mail passes authentication get an instant acknowledgement and a verdict in about two minutes. Confirmed phishing becomes a threat with a takedown drafted, waiting for your approval or filed under your signed rules.
The message you reported is a credential-phishing attempt impersonating your brand. Here's what we found.
What we found
- Sender authentication failed (SPF and DKIM)
- A link to acme-secure-login.example, a lookalike of your domain
- Matches a brand you monitor
Next steps
- Don't open the link, and warn anyone who may have.
- We've added it to your threat feed and drafted a takedown, waiting for your approval or filed under your signed rules.
Forward, triage, resolve.
Every forwarded message is checked, not just stored.
-
Forward
Customers and staff forward suspicious email to your address. Reporters whose mail passes authentication get an instant acknowledgement.
Report received Acknowledged Forwarded to verify-acme@averrow.com -
Triage
We unpack the original message, read SPF, DKIM and DMARC from the forwarded headers, extract its links and classify it.
Sender authentication Failed SPF and DKIM failedMatches a brand you monitor Matched -
Resolve
A reporter whose mail passes authentication gets a verdict in about two minutes. Phishing that our rules confirm becomes a threat, and a takedown is drafted, waiting for your approval or filed under your signed rules.
acme-secure-login.example Threat Added to your threat feedTakedown draft Awaiting approval Evidence summary attached
Forward
Customers and staff forward suspicious email to your address. Reporters whose mail passes authentication get an instant acknowledgement.
Triage
We unpack the original message, read SPF, DKIM and DMARC from the forwarded headers, extract its links and classify it.
Resolve
A reporter whose mail passes authentication gets a verdict in about two minutes. Phishing that our rules confirm becomes a threat, and a takedown is drafted, waiting for your approval or filed under your signed rules.
Live in three steps.
No software to install and no inbox to migrate. Getting protected is forwarding mail.
- We provision your address.A dedicated report address for your organisation, in the form verify-yourname@averrow.com. It is live as soon as it exists.
- Share it.Publish it where customers report fraud, and set staff to forward anything suspicious.
- Forward suspicious mail.Reports are classified on arrival. Verdicts and escalations appear in your console.
Already a customer? Your address and forwarding instructions are in the Abuse Mailbox module in your console. Log in
What the mailbox does, and what it doesn't.
Every claim on this page has a limit. These are the limits.
| Area | Covered | Not covered |
|---|---|---|
| Your address | A dedicated address for your organisation. Reports route straight into your console. | An address on your own domain. |
| Reporters | For reporters whose mail passes authentication, an instant acknowledgement, then a verdict in about two minutes. | A reply to a sender whose own mail fails authentication. We never write back to forged addresses. |
| Reading each report | The original message unpacked from the forward, its links extracted, and SPF, DKIM and DMARC read from the forwarded headers. | Certainty. A verdict is a classification, and you decide what to act on. |
| Threats and takedowns | Phishing that our rules confirm is promoted to a threat, matched to the brands you monitor, with a takedown drafted, waiting for your approval or filed under your signed rules. | Filing anything without your approval or your signed rules. |
| Noise control | Per-sender throttling, so one sender can't flood the inbox. | Replacing your mail filtering. The mailbox handles what people report. |
| Intelligence | A rollup of what your reports are surfacing: threats, providers and takedowns. | Other organisations' reports. The rollup covers your own. |
Your address
- Covered
- A dedicated address for your organisation. Reports route straight into your console.
- Not covered
- An address on your own domain.
Reporters
- Covered
- For reporters whose mail passes authentication, an instant acknowledgement, then a verdict in about two minutes.
- Not covered
- A reply to a sender whose own mail fails authentication. We never write back to forged addresses.
Reading each report
- Covered
- The original message unpacked from the forward, its links extracted, and SPF, DKIM and DMARC read from the forwarded headers.
- Not covered
- Certainty. A verdict is a classification, and you decide what to act on.
Threats and takedowns
- Covered
- Phishing that our rules confirm is promoted to a threat, matched to the brands you monitor, with a takedown drafted, waiting for your approval or filed under your signed rules.
- Not covered
- Filing anything without your approval or your signed rules.
Noise control
- Covered
- Per-sender throttling, so one sender can't flood the inbox.
- Not covered
- Replacing your mail filtering. The mailbox handles what people report.
Intelligence
- Covered
- A rollup of what your reports are surfacing: threats, providers and takedowns.
- Not covered
- Other organisations' reports. The rollup covers your own.
Where reports go next
Turn your abuse inbox into a detection feed.
Run a free domain scan, no signup. Or book a demo and we'll show you the mailbox and set up your address.