Catches impersonation
CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.
CloudCastle Email Security
CloudCastle checks who sent a message, what it asks you to do, where its links go and what its files contain. It catches fake-boss scams, phishing, spam and malware before they can hurt you.
Six coordinated engines
Email verdict
Benign · suspicious · malicious
The short version
Every new message gets several focused checks before you trust the sender, click a link or open a file.
CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.
It looks for password theft, fake invoices, payroll changes, gift-card scams and other urgent requests designed to pressure people.
Links and attachments are analyzed for threats. Inline SMTP gateway mode can act before delivery; connected mailbox mode scans new mail after delivery and quarantines detections before later review.
Best of both worlds
CloudCastle combines the architectural strengths associated with both approaches instead of reselling either product.
Perception Point and Proofpoint are referenced only to explain the design pattern. CloudCastle Email Security is our independently built engine and is not affiliated with either vendor.
The scanning pipeline
A slow or unavailable engine cannot erase the healthy findings from the others. Each layer returns evidence, status and latency to the final report.
Rspamd scores spam, sender authentication and known message patterns. CloudCastle adds its own header-alignment and VIP-identity checks even if Rspamd is unavailable.
An ONNX intent model classifies credential phishing, invoice fraud, payroll diversion, gift-card scams, extortion and malware lures. Deterministic context signals corroborate the model.
OpenCV perceptual hashes compare embedded images with a brand-logo database. Rectangle density identifies rendered login forms; QR detection catches quishing.
Threat feeds, Spamhaus DBL, SURBL and URIBL checks are combined with homoglyph and edit-distance detection for typosquatted domains. Every rewritten link is signed, scoped and expiring.
YARA and ClamAV scan attachments and bounded archive contents. Macro-capable and executable files are flagged in the report so the verdict explains exactly which file raised the risk.
The weighted aggregator combines every layer’s evidence into one score, records the contribution each engine made, and returns benign, suspicious or malicious with the reasoning attached.
Business email compromise
A forged request from the boss can be technically clean: no malicious file, no bad link, and valid SPF for the attacker’s own domain. CloudCastle looks at identity, intent and context together.
Threat coverage
Each attack class is handled by evidence designed for that attack, not by one opaque number.
Language models identify account-verification and password-reset lures while URL and vision layers inspect the destination, copied branding and rendered login form.
Rspamd’s message signals, sender authentication and reputation data separate ordinary junk from targeted social engineering without treating every marketing email as malware.
OpenCV extracts QR codes from embedded images so an attacker cannot bypass ordinary link inspection by moving the destination into a picture.
YARA, ClamAV and bounded recursive archive expansion inspect the file the recipient actually received, including nested message attachments.
A link that was safe at delivery is checked again at click time. Expiring HMAC tokens bind the original URL to its tenant and, where available, its intended recipient.
Homoglyph folding, transposition-aware edit distance and perceptual logo matching expose domains and images built to look almost legitimate.
Deployment
One CloudCastle engine. Each environment has a path that fits how its mail already flows, and each says plainly whether it checks mail before or after delivery.
Two pre-delivery choices: an inline gateway (the domain’s MX points at CloudCastle, with a Partner inbound connector and Enhanced Filtering back into Microsoft 365) or a mail-flow connector that leaves the MX exactly where it is and sends each message through CloudCastle and back before Microsoft delivers it. A tenant-wide Graph connector covers every mailbox after delivery, with no DNS change at all.
The gateway and connector paths check mail before delivery. The Graph connector reads mail Microsoft has already delivered.
Pre-delivery through an inline gateway: the domain’s MX points at CloudCastle and Google’s Admin console inbound gateway accepts mail only from it, over required TLS. Or connect the whole tenant through the Gmail API using the customer’s own Google service account and domain-wide delegation, which keeps the keys in the customer’s cloud.
The gateway path checks mail before delivery. The Gmail API connector reads mail Google has already delivered.
Dovecot, Stalwart, Exchange, cPanel mail, or a hosting provider’s mailboxes: the domain’s MX sends inbound mail through CloudCastle, which hands accepted mail to the existing host over SMTP or LMTP. Every mailbox on the routed domain is covered, with pre-queue rejection or safe delivery with mitigation.
Pre-delivery. Technician discovery confirms first that moving the MX will not disable the domain’s outbound sending — some shared-hosting providers do exactly that.
Cloudflare keeps its own MX and its own routing. An Email Worker hands every message to CloudCastle before Cloudflare forwards it, so dangerous mail is refused instead of arriving at the destination inbox.
Pre-delivery. Cloudflare cannot rewrite message bodies, so links are not wrapped for time-of-click checks on this path.
CloudCastle signs in to a selected inbox over encrypted IMAP and moves detected messages into a dedicated quarantine folder. Each credential protects one mailbox, so coverage stays explicit — useful where the provider must stay authoritative for the MX, or for a controlled first deployment.
After delivery: new mail is checked within seconds of arriving — the moment the provider announces it, or on a short poll where the provider cannot.
Connect Gmail, Outlook.com, Yahoo, AOL, iCloud, Fastmail, Zoho, Comcast/Xfinity, Spectrum, AT&T, Cox, CenturyLink, Optimum, Verizon, Frontier, EarthLink, Windstream, Mediacom, Juno or NetZero from the customer portal. CloudCastle detects the provider, verifies access, and isolates detections without a DNS change.
After delivery: new mail is checked within seconds of arriving. Mailboxes on providers that cannot move mail are reviewed from the dashboard instead.
Customers across more than 50 personal-email domains can connect one mailbox in the portal. Business customers can start with one mailbox or map a safe domain-wide route.
Simple pricing: a monthly minimum plus per inbox — see pricing.