AI-powered email threat detection, geolocation & forensic intelligence.

Investigate suspicious messages and raw email evidence with AI risk scoring, authentication analysis, infrastructure context, available geolocation signals, and analyst-ready forensic reporting.

Evidence-aware analysis
Authenticated workspaces
Scoped API keys
Explicit uncertainty states

From detection to investigation

VeriTrust does not stop at a phishing score. It keeps content, authentication, identity, URL, and infrastructure evidence separate so reviewers can see what was checked, what was unavailable, and why the final recommendation was produced.

Email Threat Intelligence

Analyze pasted message text or an original EML using MailGuard and deterministic phishing, BEC, impersonation, and lure indicators.

  • AI content likelihood plus rule evidence
  • Explicit benign, phishing, uncertain, and failed states
  • Risk kept separate from evidence completeness

Authentication & Sender Forensics

Use original-message evidence to examine DKIM, DMARC, ARC, sender-domain relationships, and trusted-receiver SPF when the required SMTP facts exist.

  • Trust-aware SPF, DKIM, DMARC, and ARC handling
  • From, Reply-To, Return-Path, and signing-domain relationships
  • Copied authentication headers are not silently trusted

Link, Relay & Evidence Correlation

Extract suspicious URLs, observe recorded mail-server infrastructure, enrich eligible public hops, and combine independent evidence without diluting strong malicious signals.

  • Swift URL specialist plus deterministic URL indicators
  • SMTP hop, ASN, provider, and approximate infrastructure GeoIP
  • Policy-backed Gateway recommendation and case review

How an email investigation works

The workflow preserves the difference between what the system observed, what it could verify, and what remains unavailable.

01

Acquire

Paste a suspicious message for fast triage or upload the original EML for header, attachment-metadata, and routing evidence.

02

Verify

Analyze content while separately checking available sender authentication and identity relationships.

03

Trace

Inspect embedded links and recorded delivery infrastructure, with approximate geolocation only for eligible public mail servers.

04

Correlate

Apply conservative evidence correlation, show limitations, and produce an analyst-ready recommendation and report.

Forensic intelligence capabilities

The current platform is centered on email evidence and investigation. Each capability retains its own provenance and limitation state instead of being flattened into one opaque score.

AI Threat Detection

MailGuard phishing likelihood plus deterministic social-engineering, credential, payment, urgency, and impersonation indicators.

Authentication Forensics

DKIM, DMARC, ARC, and trusted-receiver SPF with explicit unavailable states when the required evidence does not exist.

Sender Identity Graph

Compare visible sender, Reply-To, Return-Path, Message-ID, authentication domains, and linked domains with reason-coded relationships.

URL Intelligence

Extract URLs from email evidence and evaluate them with Swift plus deterministic indicators without requiring the reviewer to open the destination.

Relay & Geo Context

Extract observed Received-header hops and enrich eligible public infrastructure with ASN, provider, reverse-DNS, and approximate GeoIP context when available.

Evidence Correlation & Cases

Preserve strong independent risk evidence, apply policy guards, record limitations, and route consequential findings into human case review.

3

Evidence modes

4

Authentication protocols

Geo

Infrastructure, not person location

Metrics

Controlled benchmark pending

Choose the evidence level you actually have

VeriTrust never pretends that pasted text, an original EML, and a trusted SMTP receiver event provide the same forensic evidence.

Quick Content Scan

Text
  • Message wording and social-engineering indicators
  • Embedded URL extraction and intelligence
  • No header, authentication, or relay-origin claim
  • Metadata-only retention path
Paste Email Text

Trusted Receiver Evidence

SMTP
  • Trusted client IP, HELO, MAIL FROM, and receiver identity
  • SPF evaluation at the trusted boundary
  • Stronger infrastructure-origin reliability semantics
  • Integration through the documented email API
View Integration Guide

Ready to investigate a suspicious email?

Start with the evidence you have. VeriTrust will show what it can verify, what remains unavailable, and why human review may still be required.