- Rules 6
- Users 4
- Recipients 12
Mail Trend
Quarantine & Releases
Top Threat Mix
-
Graymail 417 · 36.9%
-
Spam 404 · 35.8%
-
Phishing 110 · 9.7%
-
Bec 72 · 6.4%
-
Malware 67 · 5.9%
-
Impersonation 59 · 5.2%
Top Sender Domains
-
vaalkop-steel.example 648
-
sentinel-brokers.example 332
-
rooiberg-audit.example 320
-
tygerberg-pack.example 316
-
northgate-office.example 315
-
capereach.example 309
-
vermeulen-partners.example 308
-
orbitfuel.example 297
-
halberd-eng.example 294
-
karoomutual.example 291
-
coastal-clearing.example 289
-
cargodesk-notices.example 110
-
loadline-weekly.example 103
-
depotdock-digest.example 103
-
southbound-briefing.example 101
-
global-summit-invite.example 79
-
toner-deals-direct.example 76
-
coin-signal-pro.example 72
-
rank-first-digital.example 62
-
quickcash-approve.example 62
-
growth-partners-outreach.example 53
-
karoomutual-secure.example 25 · 25 held (100%)
-
sablemere.example 24 · 24 held (100%)
-
sab1emere.example 21 · 20 held (95%)
-
secure-docs-share.example 21 · 21 held (100%)
-
sars-efiling-notice.example 18 · 18 held (100%)
-
tender-docs-za.example 18 · 17 held (94%)
-
parcel-status-update.example 18 · 18 held (100%)
-
vaalkop-stee1.example 17 · 17 held (100%)
-
hr-portal-notice.example 17 · 17 held (100%)
-
invoice-docs-secure.example 16 · 16 held (100%)
-
gmail.com 15 · 15 held (100%)
-
outlook.com 15 · 15 held (100%)
-
coastal-c1earing.example 13 · 13 held (100%)
-
ms-account-verify.example 11 · 11 held (100%)
AI Verdict Mix
- True positive386
- FP — released (remediated)3
- Benign0
- Inconclusive0
Recent Activity
- Last message
- Toner cartridges at 60% off
- Last delivery
- 2026-10-06 18:26
- Quarantine head
- Your delivery could not be completed
- Last anomaly
- 21 minutes ago
- Last rule hit
- 3 weeks ago
- AI usage
- 261 calls in 30d
Reading the scores
- +2.0DeliveredPositive or near zero. Nothing to hold it on.
- -6.0FlaggedDelivered, marked for the spam folder. Below -6.
- -15.0HeldKept out of the inbox until reviewed. Below -15, or any hard threat at any score.
Every held message shows the exact signals that moved its score, and the AI's own reading of it.
Recent Releases
- Tender pricing schedule marius.steyn@sablemere.example · 2026-09-30 05:47
- Final demand: outstanding VAT201 submission nomsa.dlamini@sablemere.example · 2026-09-11 11:18
- Quick favour payroll@sablemere.example · 2026-09-10 18:00
- RE: Invoice 22287 — updated banking details zanele.khumalo@sablemere.example · 2026-09-01 11:08
- Unusual activity on your business account payroll@sablemere.example · 2026-08-26 14:56
Health Snapshot
- Tenant statusActive
- Recipient coverage15
- AI actions609 · $0.90/30d
- Review queue0
Delivery Health last 7 days
Anomaly Detection (49)
| Marked | Cat | Subject | From | Disp | Source | Marked By | AI | Action |
|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||
DMARC=PASS + Prior Good ≥ 5 vs. Status=QUAR. Strong FP candidates. Inspect Quarantine Reason for the rule that fired and consider an allowlist or rule tune.AI & Automated Actions
| Created | Action | Reason | Subject | Verdict | OK | Detail |
|---|---|---|---|---|---|---|
| 2026-10-06 18:24 | Auto-classify | Quarantine Triage | Your delivery could not be completed | true_positive 96% |
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 17:10 | Auto-classify | Quarantine Triage | Tender pricing schedule | true_positive 97% |
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-06 15:47 | Auto-classify | Quarantine Triage | Your delivery could not be completed | true_positive 96% |
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 15:30 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 84% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-06 15:13 | Auto-classify | Quarantine Triage | Remittance advice 08/2026 | true_positive 88% |
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-06 15:02 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 88% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-06 13:34 | Auto-classify | Quarantine Triage | Quick favour | true_positive 90% |
Payment fraud: gift-card request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-06 13:32 | Auto-classify | Quarantine Triage | Are you at your desk? | true_positive 88% |
Payment fraud: executive impersonation, urgent transfer. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-06 11:53 | Auto-classify | Quarantine Triage | Accounts shared 'Remittance advice' with you | true_positive 93% |
Credential harvesting: fake document share. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 11:49 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 85% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 11:39 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 93% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-06 08:12 | Auto-classify | Quarantine Triage | RE: Invoice 22191 — updated banking details | true_positive 89% |
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-06 07:43 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 84% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 06:03 | Auto-classify | Quarantine Triage | Ashwin shared 'Remittance advice' with you | true_positive 96% |
Credential harvesting: fake document share. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-06 02:32 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 86% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-05 23:35 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 88% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-05 19:50 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 89% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-05 16:14 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 87% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-05 14:50 | Auto-classify | Quarantine Triage | Action required: re-enrol your payslip access | true_positive 86% |
Quishing: QR code resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-05 14:41 | Auto-classify | Quarantine Triage | Change of banking details for my salary | true_positive 95% |
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-05 12:30 | Auto-classify | Quarantine Triage | Remittance advice 08/2026 | true_positive 93% |
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-05 12:00 | Auto-classify | Quarantine Triage | RE: Invoice 22520 — updated banking details | true_positive 86% |
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-05 11:46 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 96% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-05 10:15 | Auto-classify | Quarantine Triage | Payment run — hold the Vaalkop invoice | true_positive 88% |
Lookalike domain carrying a director's name. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-05 10:00 | Auto-classify | Quarantine Triage | RE: Invoice 22583 — updated banking details | true_positive 86% |
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-05 07:50 | Auto-classify | Quarantine Triage | Tender pricing schedule | true_positive 97% |
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-05 03:31 | Auto-classify | Quarantine Triage | Tender pricing schedule | true_positive 87% |
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-04 16:52 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 91% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-04 16:42 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 90% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-04 13:58 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 95% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-04 13:10 | Auto-classify | Quarantine Triage | Tender pricing schedule | true_positive 96% |
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-03 02:08 | Auto-classify | Quarantine Triage | Your password expires today | true_positive 88% |
Credential harvesting: password-expiry lure. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-02 22:17 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 89% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-02 18:26 | Auto-classify | Quarantine Triage | Your delivery could not be completed | true_positive 88% |
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-02 17:09 | Auto-classify | Quarantine Triage | Remittance advice 08/2026 | true_positive 97% |
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-02 16:35 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 87% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-02 15:38 | Auto-classify | Quarantine Triage | Payment run — hold the Vaalkop invoice | true_positive 88% |
Lookalike domain carrying a director's name. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-02 14:49 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 97% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-02 12:38 | Auto-classify | Quarantine Triage | Statement of account — 45 days overdue | true_positive 95% |
Payment portal link inside the attached document. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-02 08:31 | Auto-classify | Quarantine Triage | Scanned document from the finance copier | true_positive 94% |
Antivirus detection in attachment. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-02 05:37 | Auto-classify | Quarantine Triage | Are you at your desk? | true_positive 88% |
Payment fraud: executive impersonation, urgent transfer. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-02 00:51 | Auto-classify | Quarantine Triage | Change of banking details for my salary | true_positive 96% |
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-01 19:05 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 94% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-01 17:53 | Auto-classify | Quarantine Triage | Change of banking details for my salary | true_positive 92% |
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
|
| 2026-10-01 16:46 | Auto-classify | Quarantine Triage | Remittance advice 08/2026 | true_positive 92% |
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
|
|
| 2026-10-01 16:32 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 90% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-01 14:12 | Auto-classify | Quarantine Triage | Unusual activity on your business account | true_positive 84% |
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
|
|
| 2026-10-01 12:50 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 95% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-01 11:26 | Auto-classify | Quarantine Triage | Final demand: outstanding VAT201 submission | true_positive 92% |
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
|
|
| 2026-10-01 09:38 | Auto-classify | Quarantine Triage | Quick favour | true_positive 93% |
Payment fraud: gift-card request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
|
Filtering Rules
| Priority | Category | Name | Conditions | Actions | Exceptions | Status | Triggers | Last Triggered |
|---|---|---|---|---|---|---|---|---|
| 10 | security | Block executable attachments | 1 | 1 | — | Enabled | 0 | 1 month ago |
| 15 | business | Allow the audit firm during year end | 1 | 1 | — | Disabled | 0 | Never |
| 20 | payment-fraud | Hold banking-change claims from outside the supplier list | 2 | 1 | — | Enabled | 0 | 1 month ago |
| 30 | phishing | Hold password-reset lures | 1 | 1 | — | Enabled | 0 | 1 month ago |
| 40 | security | Quarantine macro-enabled documents | 1 | 1 | — | Enabled | 0 | 3 weeks ago |
| 60 | hygiene | Tag newsletters | 1 | 1 | — | Enabled | 0 | 3 weeks ago |
Filter Lists
Named sets of addresses, domains or filename patterns that this tenant's
rules reference with the is in list / is not in list
conditions — so a long allowlist is entered once instead of retyped into
every rule.
Bypassed Senders (1)
| Sender | Type | Authentication | Status | Added | Note |
|---|---|---|---|---|---|
| noreply@karoomutual.example | Required | Active |
nomsa.dlamini@sablemere.example
2026-09-09 |
Bank statement notifications. DMARC must pass for this to apply. |
Tenant Users
| Name | Role | Status | |
|---|---|---|---|
craig.bester@sablemere.example |
Craig Bester | TENANT_VIEWER | Active |
lerato.molefe@sablemere.example |
Lerato Molefe | TENANT_VIEWER | Active |
pieter.vanwyk@sablemere.example |
Pieter van Wyk | TENANT_MANAGER | Active |
nomsa.dlamini@sablemere.example |
Nomsa Dlamini | TENANT_ADMIN | Active |
Domain Ratings (0 domains) — showing most recent 0 of 32 (type a domain and press Enter to search all)
No domains found
Sender domains will appear here as emails are processed
Rating Legend
- ≥ 0 = Good reputation
- < 0 = Bad reputation
- +0.1 per delivered
- -1.0 per phishing/malware quarantine
- -0.1 per other quarantine
- > 0 = Trusted
- < 0 = High Risk
- Green = Allow-listed domain
- Red = Blocked domain
- Allow = Add to allow list
- Block = Add to block list
Platform Policies
Configure trust policies for common email platforms| Platform | Policy Type | Score Adjustment | Created By | Created At | |
|---|---|---|---|---|---|
| No platform policies configured. | |||||
Allow List
Trusted sender domains or specific addresses receive a positive score adjustment (trust boost). Email-address entries override domain-level policies.
| Domain / Email | Score | Status | Actions |
|---|---|---|---|
|
capereach.example
Established supplier, verified by Finance. |
+15 | Active |
|
|
coastal-clearing.example
Established supplier, verified by Finance. |
+15 | Active |
|
|
halberd-eng.example
Established supplier, verified by Finance. |
+15 | Active |
|
|
karoomutual.example
Established supplier, verified by Finance. |
+15 | Active |
|
|
northgate-office.example
Established supplier, verified by Finance. |
+15 | Active |
|
|
orbitfuel.example
Established supplier, verified by Finance. |
+15 | Active |
|
Block List
Blocked sender domains or specific addresses receive a negative score adjustment (distrust). Email-address entries override domain-level policies.
| Domain / Email | Score | Status | Actions |
|---|---|---|---|
|
coastal-c1earing.example
Used in an impersonation attempt against this tenant. |
-25 | Active |
|
|
karoomutual-secure.example
Used in an impersonation attempt against this tenant. |
-25 | Active |
|
|
ms-account-verify.example
Used in an impersonation attempt against this tenant. |
-25 | Active |
|
|
vaalkop-stee1.example
Used in an impersonation attempt against this tenant. |
-25 | Active |
|
Protected VIPs (3)
| Name | Addresses (primary + alternates they send from) | Status |
|---|---|---|
| Craig Bester |
craig.bester@sablemere.example
|
Active |
| Nomsa Dlamini |
nomsa.dlamini@sablemere.example
n.dlamini@sablemere-board.example
|
Active |
| Pieter van Wyk |
pieter.vanwyk@sablemere.example
|
Active |
Domains exempt from VIP checks (0)
Mail from these domains keeps its VIP name check off — so
“Jane Smith via Adobe Acrobat Sign” is not held as impersonation.
Applies only when SPF, DKIM and DMARC all pass and the sender is
not spoofing one of your own domains; a listed domain that fails
authentication is still held, and the refusal is logged. Everything else about
the message is still scanned and scored. Exact domain only —
eu1.adobesign.com needs its own entry. Consumer webmail
(gmail.com, outlook.com…) cannot be exempted.
Danger Zone
Irreversible actionsDelete Tenant
Permanently delete this tenant and all associated data