AI-powered email threat detection, geolocation & forensic intelligence.
Investigate suspicious messages and raw email evidence with AI risk scoring, authentication analysis, infrastructure context, available geolocation signals, and analyst-ready forensic reporting.
From detection to investigation
VeriTrust does not stop at a phishing score. It keeps content, authentication, identity, URL, and infrastructure evidence separate so reviewers can see what was checked, what was unavailable, and why the final recommendation was produced.
Email Threat Intelligence
Analyze pasted message text or an original EML using MailGuard and deterministic phishing, BEC, impersonation, and lure indicators.
- AI content likelihood plus rule evidence
- Explicit benign, phishing, uncertain, and failed states
- Risk kept separate from evidence completeness
Authentication & Sender Forensics
Use original-message evidence to examine DKIM, DMARC, ARC, sender-domain relationships, and trusted-receiver SPF when the required SMTP facts exist.
- Trust-aware SPF, DKIM, DMARC, and ARC handling
- From, Reply-To, Return-Path, and signing-domain relationships
- Copied authentication headers are not silently trusted
Link, Relay & Evidence Correlation
Extract suspicious URLs, observe recorded mail-server infrastructure, enrich eligible public hops, and combine independent evidence without diluting strong malicious signals.
- Swift URL specialist plus deterministic URL indicators
- SMTP hop, ASN, provider, and approximate infrastructure GeoIP
- Policy-backed Gateway recommendation and case review
How an email investigation works
The workflow preserves the difference between what the system observed, what it could verify, and what remains unavailable.
Acquire
Paste a suspicious message for fast triage or upload the original EML for header, attachment-metadata, and routing evidence.
Verify
Analyze content while separately checking available sender authentication and identity relationships.
Trace
Inspect embedded links and recorded delivery infrastructure, with approximate geolocation only for eligible public mail servers.
Correlate
Apply conservative evidence correlation, show limitations, and produce an analyst-ready recommendation and report.
Forensic intelligence capabilities
The current platform is centered on email evidence and investigation. Each capability retains its own provenance and limitation state instead of being flattened into one opaque score.
AI Threat Detection
MailGuard phishing likelihood plus deterministic social-engineering, credential, payment, urgency, and impersonation indicators.
Authentication Forensics
DKIM, DMARC, ARC, and trusted-receiver SPF with explicit unavailable states when the required evidence does not exist.
Sender Identity Graph
Compare visible sender, Reply-To, Return-Path, Message-ID, authentication domains, and linked domains with reason-coded relationships.
URL Intelligence
Extract URLs from email evidence and evaluate them with Swift plus deterministic indicators without requiring the reviewer to open the destination.
Relay & Geo Context
Extract observed Received-header hops and enrich eligible public infrastructure with ASN, provider, reverse-DNS, and approximate GeoIP context when available.
Evidence Correlation & Cases
Preserve strong independent risk evidence, apply policy guards, record limitations, and route consequential findings into human case review.
3
Evidence modes
4
Authentication protocols
Geo
Infrastructure, not person location
Metrics
Controlled benchmark pending
Choose the evidence level you actually have
VeriTrust never pretends that pasted text, an original EML, and a trusted SMTP receiver event provide the same forensic evidence.
Quick Content Scan
- Message wording and social-engineering indicators
- Embedded URL extraction and intelligence
- No header, authentication, or relay-origin claim
- Metadata-only retention path
Full EML Investigation
- Bounded MIME and header parsing
- DKIM, DMARC, ARC, identity, links, and attachments metadata
- Recorded relay infrastructure and approximate GeoIP when available
- SPF remains unavailable without trusted SMTP facts
Trusted Receiver Evidence
- Trusted client IP, HELO, MAIL FROM, and receiver identity
- SPF evaluation at the trusted boundary
- Stronger infrastructure-origin reliability semantics
- Integration through the documented email API
Ready to investigate a suspicious email?
Start with the evidence you have. VeriTrust will show what it can verify, what remains unavailable, and why human review may still be required.