CloudCastle Email Security

Every message gets a second opinion

CloudCastle checks who sent a message, what it asks you to do, where its links go and what its files contain. It catches fake-boss scams, phishing, spam and malware before they can hurt you.

Six coordinated engines

The short version

What Email Security does for you

Every new message gets several focused checks before you trust the sender, click a link or open a file.

Identity

Catches impersonation

CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.

Intent

Understands the request

It looks for password theft, fake invoices, payroll changes, gift-card scams and other urgent requests designed to pressure people.

Content

Checks links and files

Links and attachments are analyzed for threats. Inline SMTP gateway mode can act before delivery; connected mailbox mode scans new mail after delivery and quarantines detections before later review.

Best of both worlds

Perception Point speed. Proofpoint depth. Built in house.

CloudCastle combines the architectural strengths associated with both approaches instead of reselling either product.

Perception Point-style inline analysis

Understand the message immediately

  • ONNX language models classify BEC and phishing intent
  • Computer vision recognizes copied logos, login forms and QR-code lures
  • Header alignment exposes display-name, Reply-To and envelope deception
  • Independent engines run concurrently under individual time budgets
Proofpoint-style defense in depth

Keep checking after the first scan

  • Rewritten links are checked again at the exact moment of the click
  • YARA and ClamAV inspect attachments locally the moment a message arrives
  • Archives are expanded recursively so nested payloads are scanned too
  • Reputation feeds, DNS blocklists and lookalike-domain detection corroborate risk

Perception Point and Proofpoint are referenced only to explain the design pattern. CloudCastle Email Security is our independently built engine and is not affiliated with either vendor.

The scanning pipeline

Six views of the same email. One explainable verdict.

A slow or unavailable engine cannot erase the healthy findings from the others. Each layer returns evidence, status and latency to the final report.

Layer 1

Message reputation

Rspamd scores spam, sender authentication and known message patterns. CloudCastle adds its own header-alignment and VIP-identity checks even if Rspamd is unavailable.

Layer 2

Language intelligence

An ONNX intent model classifies credential phishing, invoice fraud, payroll diversion, gift-card scams, extortion and malware lures. Deterministic context signals corroborate the model.

Layer 2

Computer vision

OpenCV perceptual hashes compare embedded images with a brand-logo database. Rectangle density identifies rendered login forms; QR detection catches quishing.

Layer 3

URL defense

Threat feeds, Spamhaus DBL, SURBL and URIBL checks are combined with homoglyph and edit-distance detection for typosquatted domains. Every rewritten link is signed, scoped and expiring.

Layer 3

Attachment analysis

YARA and ClamAV scan attachments and bounded archive contents. Macro-capable and executable files are flagged in the report so the verdict explains exactly which file raised the risk.

Layer 4

Weighted verdict

The weighted aggregator combines every layer’s evidence into one score, records the contribution each engine made, and returns benign, suspicious or malicious with the reasoning attached.

Business email compromise

BEC has no malware. We still see it.

A forged request from the boss can be technically clean: no malicious file, no bad link, and valid SPF for the attacker’s own domain. CloudCastle looks at identity, intent and context together.

  • VIP impersonation: a protected executive or help-desk name must come from its registered domain, including common homoglyph tricks.
  • Routing deception: From, Reply-To, Return-Path and SMTP envelope domains are compared independently.
  • Financial intent: invoice, wire-transfer, payroll and banking-change language is classified separately from ordinary spam.
  • Correlated evidence: urgency, authority claims, credential requests and domain mismatch must reinforce one another; one keyword cannot convict a message.
A suspicious sign-in request and impersonated identity being detected

Threat coverage

More than a spam score

Each attack class is handled by evidence designed for that attack, not by one opaque number.

Phishing

Credential theft

Language models identify account-verification and password-reset lures while URL and vision layers inspect the destination, copied branding and rendered login form.

Spam

Bulk and nuisance mail

Rspamd’s message signals, sender authentication and reputation data separate ordinary junk from targeted social engineering without treating every marketing email as malware.

Quishing

QR-code attacks

OpenCV extracts QR codes from embedded images so an attacker cannot bypass ordinary link inspection by moving the destination into a picture.

Malware

Weaponized files

YARA, ClamAV and bounded recursive archive expansion inspect the file the recipient actually received, including nested message attachments.

URL defense

Late-armed websites

A link that was safe at delivery is checked again at click time. Expiring HMAC tokens bind the original URL to its tenant and, where available, its intended recipient.

Brand abuse

Lookalikes and copied logos

Homoglyph folding, transposition-aware edit distance and perceptual logo matching expose domains and images built to look almost legitimate.

Deployment

Your email service, named

One CloudCastle engine. Each environment has a path that fits how its mail already flows, and each says plainly whether it checks mail before or after delivery.

Microsoft 365

Inline gateway, mail-flow connector, or tenant-wide

Two pre-delivery choices: an inline gateway (the domain’s MX points at CloudCastle, with a Partner inbound connector and Enhanced Filtering back into Microsoft 365) or a mail-flow connector that leaves the MX exactly where it is and sends each message through CloudCastle and back before Microsoft delivers it. A tenant-wide Graph connector covers every mailbox after delivery, with no DNS change at all.

The gateway and connector paths check mail before delivery. The Graph connector reads mail Microsoft has already delivered.

Google Workspace

Inline gateway or tenant-wide Gmail API

Pre-delivery through an inline gateway: the domain’s MX points at CloudCastle and Google’s Admin console inbound gateway accepts mail only from it, over required TLS. Or connect the whole tenant through the Gmail API using the customer’s own Google service account and domain-wide delegation, which keeps the keys in the customer’s cloud.

The gateway path checks mail before delivery. The Gmail API connector reads mail Google has already delivered.

Self-hosted or any other provider

Inline gateway

Dovecot, Stalwart, Exchange, cPanel mail, or a hosting provider’s mailboxes: the domain’s MX sends inbound mail through CloudCastle, which hands accepted mail to the existing host over SMTP or LMTP. Every mailbox on the routed domain is covered, with pre-queue rejection or safe delivery with mitigation.

Pre-delivery. Technician discovery confirms first that moving the MX will not disable the domain’s outbound sending — some shared-hosting providers do exactly that.

Cloudflare Email Routing

Email Worker

Cloudflare keeps its own MX and its own routing. An Email Worker hands every message to CloudCastle before Cloudflare forwards it, so dangerous mail is refused instead of arriving at the destination inbox.

Pre-delivery. Cloudflare cannot rewrite message bodies, so links are not wrapped for time-of-click checks on this path.

One business mailbox

Connected mailbox (IMAP)

CloudCastle signs in to a selected inbox over encrypted IMAP and moves detected messages into a dedicated quarantine folder. Each credential protects one mailbox, so coverage stays explicit — useful where the provider must stay authoritative for the MX, or for a controlled first deployment.

After delivery: new mail is checked within seconds of arriving — the moment the provider announces it, or on a short poll where the provider cannot.

Personal mailboxes

Gmail, Outlook.com, Yahoo, AOL, iCloud and 50+ more

Connect Gmail, Outlook.com, Yahoo, AOL, iCloud, Fastmail, Zoho, Comcast/Xfinity, Spectrum, AT&T, Cox, CenturyLink, Optimum, Verizon, Frontier, EarthLink, Windstream, Mediacom, Juno or NetZero from the customer portal. CloudCastle detects the provider, verifies access, and isolates detections without a DNS change.

After delivery: new mail is checked within seconds of arriving. Mailboxes on providers that cannot move mail are reviewed from the dashboard instead.

Put CloudCastle between you and the next bad email

Customers across more than 50 personal-email domains can connect one mailbox in the portal. Business customers can start with one mailbox or map a safe domain-wide route.

Simple pricing: a monthly minimum plus per inbox — see pricing.