For fraud and customer-trust teams

Turn what customers report into takedowns.

Give customers and staff one address to forward suspicious email to, and have the phishing sites behind it drafted for takedown, filed only with your approval or under your signed rules.

Illustrative Fictional brand, example domains
Report received Acknowledged Forwarded by a customer
acme-secure-login.example Threat Phishing confirmed by our rules. Added to your threat feed.
Takedown draft Awaiting approval Evidence summary attached
Nothing is filed without your approval or your signed rules
Abuse Mailbox · Enterprise

One address to report suspicious email.

Customers already forward what looks wrong. The mailbox reads it, classifies it and tells you whether it's phishing aimed at your brand.

  • One address. Your organisation gets a dedicated Averrow address, set up by our team. Customers and staff forward suspicious email to it.
  • Every report is read. We unpack the original message, read SPF, DKIM and DMARC from the forwarded headers, extract its links and classify it automatically.
  • Reporters hear back. A reporter whose own mail passes authentication gets an acknowledgement, then a verdict. We never write back to a sender whose mail fails authentication.
  • Phishing becomes a threat. Phishing that our rules confirm is added to your threat feed, matched to the brands you monitor, with a takedown drafted for your approval.
Illustrative Fictional brand, example domains
Report received Acknowledged Forwarded to your Averrow address
Sender authentication Failed SPF and DKIM failed
Matches a brand you monitor Matched
acme-secure-login.example Threat Added to your threat feed
Reports route straight into your console

See the Abuse Mailbox in full, including setup.

Phishing-site takedowns · Professional+

Filed only with your say.

Every phishing site we find, from a report or from our own monitoring, can be drafted for takedown. You choose how much runs on its own.

  • Off

    Manual

    You approve each one, and we file it. Nothing goes out automatically.

  • Semi-auto

    Approval for anything outside your rules

    Takedowns outside your rules wait until someone on your team approves them.

  • Auto

    Within your signed scope

    Filed automatically within your signed scope and any monthly limit you set.

Illustrative Fictional brand, example domains
acme-secure-login.example Draft Waiting for your approval
acme-payroll-login.example Submitted Report sent to the registrar, ticket 48213
acme-login-help.example Taken down Re-checked, alert if it returns
Nothing is filed without your approval or your signed rules

See how takedowns work, including every status.

Scope

What's covered, and what isn't.

Every claim on this page has a limit. These are the limits.

Fraud and customer trust: covered and not covered
Area Covered Not covered
Abuse Mailbox Enterprise only. A dedicated Averrow address for your organisation, with reports routed into your console. An address on your own domain, and any plan below Enterprise.
Reading reports Each message is unpacked, its authentication headers read, its links extracted and the report classified automatically. Certainty. A verdict is a classification, and you decide what to act on.
Replies Acknowledgement and verdict to reporters whose own mail passes authentication. A reply to a sender whose mail fails authentication, and a promised reply time.
Phishing-site takedowns Professional+. Abuse reports for lookalike domains and phishing URLs, with an evidence summary, filed with your approval or under your signed rules. Filing without your approval or signed rules, and a promise that a provider will remove a site. Removal is the provider's decision.
Stay-down Removed domains are re-checked, and you're alerted if one returns. A guarantee that a removed domain stays down.

Abuse Mailbox

Covered
Enterprise only. A dedicated Averrow address for your organisation, with reports routed into your console.
Not covered
An address on your own domain, and any plan below Enterprise.

Reading reports

Covered
Each message is unpacked, its authentication headers read, its links extracted and the report classified automatically.
Not covered
Certainty. A verdict is a classification, and you decide what to act on.

Replies

Covered
Acknowledgement and verdict to reporters whose own mail passes authentication.
Not covered
A reply to a sender whose mail fails authentication, and a promised reply time.

Phishing-site takedowns

Covered
Professional+. Abuse reports for lookalike domains and phishing URLs, with an evidence summary, filed with your approval or under your signed rules.
Not covered
Filing without your approval or signed rules, and a promise that a provider will remove a site. Removal is the provider's decision.

Stay-down

Covered
Removed domains are re-checked, and you're alerted if one returns.
Not covered
A guarantee that a removed domain stays down.
Related

The platform behind this role

Other roles

Where the work gets shared

Make every report count.

Run a free domain scan, no signup. Or book a demo and we'll show you the Abuse Mailbox and the approval queue.