| Platform | Ironscales, integrated with your mail platform rather than bolted in front of it, which is what makes post-delivery removal possible at all. |
|---|---|
| Filtering | Junk and malware screening, content rules of your own, and outbound checks so a compromised account of yours does not become somebody else's incident. |
| Links | Reputation and predictive analysis on embedded links, including the respectable-looking address that is weaponized after delivery. |
| Attachments | Reputation scoring and sandbox detonation before the file reaches a human being. |
| Impostor and BEC | Detection of display-name spoofing, look-alike domains, and the payment-redirection message that carries no attachment, no link, and nothing for a scanner to find. |
| Warning tags | Banners printed into the message where it is read, which is the only moment a warning can still change anything. |
| Removal | One click retracts a message from every inbox it landed in, opened ones included. |
| Training | The awareness program below is included in this line. |
| How it bills | Monthly, against each mailbox. |
| Simulation | Unlimited phishing tests, run continuously rather than as an annual event everybody warns each other about. |
|---|---|
| Campaigns | Automated training assignment, short prompts, and remedial content that follows a failed test instead of arriving nine months later. |
| Report button | A one-click report control inside the mail client. Reply tracking closes the loop, and the effect is to turn your own staff into the reporting sensor most estates lack. |
| Directory | Active Directory integration so the roster maintains itself as people join and leave. |
| Reporting | Results by person and by department, benchmarking against your industry, a monthly check on how exposed your addresses are, and indicators of social engineering. |
| When to buy it alone | For organizations whose mail filtering is already contracted elsewhere and cannot be moved. Otherwise take Fortify-FES+SAT, which already includes this. |
| How it bills | Monthly, against each user. |
The message that steals money contains nothing to detect
A wire fraud attempt is a short, polite, plausible message from a name the reader knows, asking for something the reader routinely does. There is no attachment, no link, and no payload. Every technical control designed to find something bad in the message finds nothing, correctly, and delivers it.
Meanwhile the credential phishing page is a pixel-perfect copy of your own sign-in screen hosted on a domain registered forty minutes ago with a valid certificate. The lock icon has meant nothing about honesty for years, and the people we ask to spot these things have a job that is not this.
Sitting inside the mailbox rather than in front of it
The platform connects to Microsoft 365 or Google Workspace directly, rather than standing in the mail path as a gateway. That distinction does real work. A gateway gets exactly one opportunity to judge a message, at delivery, and no ability to revisit it. Mail records are not rewritten and internal mail between your own staff does not bypass inspection.
More usefully, judgment is not final. When a message is reclassified after delivery, whether by analysis or because one alert employee reported it, the same message can be lifted out of every inbox it reached, opened ones included. Nobody has to be told to go and delete anything.
Warning at the moment of reading, not in a policy document
Contextual banners appear on the message itself: an external sender, a first-time correspondent, a display name that does not match the address behind it, a reply path that goes somewhere other than the apparent sender.
This is unglamorous and it works, because it arrives at the only moment a warning is capable of changing a decision. Security guidance delivered in a slide deck in March is not present in the room when the invoice arrives in September.
Rehearsal, and a reporting habit worth more than the training
Simulations run continuously and unpredictably, which is the only way results mean anything. A once-a-year exercise measures how quickly your staff warn each other, which is admirable and tells you nothing.
The report button is the part with the highest return. Every reported message is an early warning from inside your own organization, arriving before the campaign has finished landing. Reply tracking closes the loop so the reporter learns what happened, and people who learn what happened report again. An estate where reporting is routine detects campaigns faster than one relying only on filtering.
Post-delivery removal is the capability that pays for the line
Every mail defense fails occasionally, and the useful question is what can be done in the twenty minutes afterwards. A gateway that has already delivered a message has nothing left to offer. Integrated mail defense can reach back in and retract it from every mailbox at once.
That single capability changes a phishing campaign from an incident into an errand, and it is the reason we sell mail defense that sits inside the platform rather than in front of it.
Where this Article stops
- Coverage is mailboxes on Microsoft 365 or Google Workspace. Mail systems you run yourself are quoted separately, not assumed.
- Fraud arriving by telephone, text message, or a chat platform is outside this Article. The training component covers those techniques; the filtering cannot see them.
- No control here prevents an authorized person from deliberately approving a payment after being convincingly deceived. Banners, training, and your own second-signature rule are what stand between that call and the money.
- Mail defense does not protect the contents of the mailbox itself. Retention and restore belong to Article VI.
- Buying both lines together is usually waste. Fortify-FES+SAT already carries the training.