Skip to main content
Email Security

Stop the threats your inbox quietly lets through.

AI-powered classification routes every message through multiple detection engines quarantining or releasing based on real intent, not just keywords.

99.4%
Threats blocked
<1m
Time to quarantine
M365 · Workspace
Native API integration
What's included

A complete service, run by people.

Phishing & BEC

Detect domain look-alikes, payload links, and impersonation in real time.

AI intent analysis

Classify message tone, urgency, and ask catching social engineering keywords miss.

Account takeover

Internal email scanning catches compromised accounts before they spread.

Native deployment

API-based no MX changes, no broken calendar invitations, no headaches.

User reporting

One-click 'report phish' button with analyst feedback in minutes.

Continuous training

Targeted simulations based on the threats actually hitting your team.

BEC in Canada

Business email compromise targeting Canadian SMBs

BEC is the highest-dollar cybercrime category in Canada, ahead of ransomware, per the Canadian Anti-Fraud Centre, which recorded over CAD $90 million in reported losses in 2023, a figure that understates reality since only 5-10% of fraud incidents are ever reported. It isn't a technical attack: it exploits trust and urgency rather than software vulnerabilities, which makes it invisible to perimeter firewalls and standard antivirus.

Attack Patterns

Four BEC patterns targeting Canadian SMBs

Standard tools like Exchange Online Protection rely on sender reputation and attachment scanning, controls that fail against BEC because these messages contain no links, no attachments, and originate from domains with no negative reputation yet.

  • CEO fraud: An attacker impersonates a senior executive via a spoofed or lookalike domain to instruct accounts-payable to wire funds or change vendor banking details.
  • Invoice fraud: A supplier's email account is compromised or spoofed to redirect a legitimate payment, often discovered only when the real supplier follows up on an overdue invoice.
  • Payroll diversion: An attacker impersonates an employee to redirect a direct deposit to an account they control.
  • Credential phishing: Fake M365 or Google Workspace login pages harvest credentials that then enable all three attacks above from inside the organization's actual domain.
Email Authentication

DMARC, DKIM, and SPF: what each one does and why all three matter

  • SPF (Sender Policy Framework): SPF is a DNS record that lists which mail servers are authorized to send email on behalf of your domain. When a receiving mail server gets a message claiming to be from your domain, it checks the sending server's IP address against your SPF record. A strict SPF policy ("~all" or "-all") instructs receiving servers to treat mail from unauthorized sources with suspicion or reject it outright. SPF stops basic spoofing of the envelope-from address but does not protect the visible From header in email clients, the header that users actually see.
  • DKIM (DomainKeys Identified Mail): DKIM adds a cryptographic signature to outgoing messages using a private key stored on your mail server. The corresponding public key is published in your DNS. Receiving servers verify the signature against the public key to confirm that the message body and headers have not been modified in transit and that the message originated from a server with access to your private signing key. DKIM protects message integrity and provides a verifiable link between the message and your domain, but alone, it does not tell receiving servers what to do with messages that fail the check.
  • DMARC (Domain-based Message Authentication, Reporting & Conformance): DMARC builds on SPF and DKIM by adding policy and reporting. A DMARC record tells receiving mail servers what action to take when a message fails SPF and DKIM alignment (none / quarantine / reject) and where to send aggregate and forensic reports about authentication results. A DMARC policy of "reject" is the goal: it instructs all receiving mail servers to block messages that claim to be from your domain but cannot pass SPF or DKIM verification. Without DMARC at enforcement, SPF and DKIM alone provide intelligence but no protection.
  • What happens without SPF: Without SPF, any mail server on the internet can send email claiming to be from your domain with no technical barrier. Attackers use this to send phishing emails from your domain to your customers and partners, impersonate your CEO in BEC attacks against your own suppliers, and conduct credential phishing campaigns that appear to originate from your company's legitimate email address. Your domain reputation suffers regardless of whether the recipient reports the attack.
  • What happens without DMARC at enforcement: Many organizations have SPF and DKIM configured but leave DMARC at policy "none" (monitoring-only mode) indefinitely. This is the worst of both worlds: you receive reports showing your domain is being actively spoofed, but you have taken no action to stop it. DMARC in monitoring mode with no path to enforcement provides no protection. It is a common configuration left in place because moving to "reject" policy requires validating that all legitimate sending sources are authenticated, a process that requires coordination across marketing tools, CRM platforms, and transactional email providers, but that takes hours, not weeks, for most SMBs.
  • Cyber insurer and M365 licensing requirements: DMARC at enforcement (policy "quarantine" or "reject") is now a listed requirement in the application questionnaires for most Canadian cyber insurance carriers. Microsoft's Secure Score framework also flags the absence of DMARC enforcement as a high-priority finding. A domain without DMARC enforcement that is actively being spoofed for phishing attacks against third parties creates potential civil liability in addition to the direct damage to your domain reputation, recipients of fraudulent mail purportedly from your domain have recourse against you if the attack could have been prevented by standard authentication controls.
PIPEDA and Email

Email security obligations under PIPEDA

Email is the leading initial access vector in reported Canadian privacy breaches, and PIPEDA's breach reporting rules require notifying the OPC and affected individuals whenever an incident creates a real risk of significant harm. Organizations with no email security logging, no record of what messages were received or which accounts were accessed after a phishing event, can't produce the notification detail the OPC requires; AI-powered email platforms that log every detection and quarantine action serve as the evidence base for that notification.

Notification Timelines

How fast you need to notify, and who

StandardTimelineApplies to
PIPEDA (federal)"As soon as feasible", no fixed window, but delay counts against youAll organizations reporting to the OPC
De facto Canadian benchmark72 hoursStandard used by most Canadian privacy counsel, derived from GDPR convergence
Law 25 (Quebec)72 hours, statutoryAny organization doing business with Quebec residents
Outcomes

What changes after week one.

You'll feel the difference fast fewer alerts, faster response, and a clearer picture of where your real risk lives.

  • Cut phishing dwell time from hours to under a minute
  • Stop wire-transfer fraud and invoice redirection attempts
  • Detect compromised accounts before they email your customers
  • Reduce IT helpdesk 'is this email safe?' tickets by 80%
  • Give your team confidence in every message in their inbox
How it works

From kickoff to coverage in days.

Step 01
Connect

API integration with M365 or Workspace live in under an hour.

Step 02
Learn

We baseline your normal communication patterns over 7 days.

Step 03
Protect

Block, quarantine, or banner messages based on real risk.

Step 04
Train

Targeted simulations and reporting close the human gap.

FAQ

Common questions, answered.

The things buyers ask us most about scope, onboarding, and what you'll see in your monthly report.

Ask us anything

Make your inbox the safest place to work.

Run a 14-day shadow analysis on your live mail flow. See exactly what your current filter is missing.