CyberFrame SIFT Demo · sample data cyberframe.co.za Scan your own email Talk to us
Tenant Overview

Sablemere Freight (Pty) Ltd

Active Sample data
sablemere.example Invented company, real engine Last mail 2026-10-06 18:26
Mail Volume
7,192 -3% wk
1,106 this week · 460 quarantined
Quarantine Pressure
6.4% +16% wk
74 held this week
Insights
49
0.68% of mail flagged
Policy Footprint
  • Rules 6
  • Users 4
  • Recipients 12
This week 1106 messages, down 3% vs last week 74 held (+16%) 1 released Top threat: Graymail (37% of flagged) AI: 67 verdicts — 67 threats confirmed
Mail Trend
1312 mail / 7d 4848 mail / 30d 82 quarantined / 7d Mail Quarantined
09-06 09-21 10-06
Quarantine & Releases
305 quarantined / 30d 3 released / 30d Quarantined Released
09-06 09-21 10-06
Top Threat Mix
  • Graymail 417 · 36.9%
  • Spam 404 · 35.8%
  • Phishing 110 · 9.7%
  • Bec 72 · 6.4%
  • Malware 67 · 5.9%
  • Impersonation 59 · 5.2%
Top Sender Domains
  • vaalkop-steel.example 648
  • sentinel-brokers.example 332
  • rooiberg-audit.example 320
  • tygerberg-pack.example 316
  • northgate-office.example 315
  • capereach.example 309
  • vermeulen-partners.example 308
  • orbitfuel.example 297
  • halberd-eng.example 294
  • karoomutual.example 291
  • coastal-clearing.example 289
  • cargodesk-notices.example 110
  • loadline-weekly.example 103
  • depotdock-digest.example 103
  • southbound-briefing.example 101
  • global-summit-invite.example 79
  • toner-deals-direct.example 76
  • coin-signal-pro.example 72
  • rank-first-digital.example 62
  • quickcash-approve.example 62
  • growth-partners-outreach.example 53
  • karoomutual-secure.example 25 · 25 held (100%)
  • sablemere.example 24 · 24 held (100%)
  • sab1emere.example 21 · 20 held (95%)
  • secure-docs-share.example 21 · 21 held (100%)
  • sars-efiling-notice.example 18 · 18 held (100%)
  • tender-docs-za.example 18 · 17 held (94%)
  • parcel-status-update.example 18 · 18 held (100%)
  • vaalkop-stee1.example 17 · 17 held (100%)
  • hr-portal-notice.example 17 · 17 held (100%)
  • invoice-docs-secure.example 16 · 16 held (100%)
  • gmail.com 15 · 15 held (100%)
  • outlook.com 15 · 15 held (100%)
  • coastal-c1earing.example 13 · 13 held (100%)
  • ms-account-verify.example 11 · 11 held (100%)
AI Verdict Mix
  • True positive386
  • FP — released (remediated)3
  • Benign0
  • Inconclusive0
Remediated: 0 by AI · 6 by humans
Actual FP rate 1.0% (3 human-confirmed of 308 held) — healthy.
Review coverage: 261/308 held messages AI-investigated (85%).
Recent Activity
Last message
Toner cartridges at 60% off
Last delivery
2026-10-06 18:26
Quarantine head
Your delivery could not be completed
Last anomaly
21 minutes ago
Last rule hit
3 weeks ago
AI usage
261 calls in 30d
Reading the scores
  • +2.0
    DeliveredPositive or near zero. Nothing to hold it on.
  • -6.0
    FlaggedDelivered, marked for the spam folder. Below -6.
  • -15.0
    HeldKept out of the inbox until reviewed. Below -15, or any hard threat at any score.

Every held message shows the exact signals that moved its score, and the AI's own reading of it.

Recent Releases
0 / 24h 1 / 7d 3 / 30d
  • Tender pricing schedule marius.steyn@sablemere.example · 2026-09-30 05:47
  • Final demand: outstanding VAT201 submission nomsa.dlamini@sablemere.example · 2026-09-11 11:18
  • Quick favour payroll@sablemere.example · 2026-09-10 18:00
  • RE: Invoice 22287 — updated banking details zanele.khumalo@sablemere.example · 2026-09-01 11:08
  • Unusual activity on your business account payroll@sablemere.example · 2026-08-26 14:56
Health Snapshot
  • Tenant statusActive
  • Recipient coverage15
  • AI actions609 · $0.90/30d
  • Review queue0
Loading quarantine…
Loading email log…
Delivery Health last 7 days
No delivery failures
Mail accepted by the gateway but bounced / deferred / failed at the downstream mailserver.
6.7% quarantined
75 of 1127 messages held in the last 7 days.
Anomaly Detection (49)
No anomalies detected in the last 90 days across any of the 12 categories.
Classified items. Every anomaly row already marked TP / FP / Benign / Under Review. Source human = admin click; ai = auto-classified from a GPT verdict above threshold. Unmark returns the row to its category.
Marked Cat Subject From Disp Source Marked By AI Action
Loading…
A1 — High-Score Delivered. Scored ≥ quarantine threshold (15.0) but delivered because domain reputation overrode the verdict. Review whether the sender domain policy needs tightening.
No anomalies detected in the selected period.
A2 — Quarantined Clean Domain. Quarantined despite 5+ good deliveries from this sender domain and ≤2 bad. Spoofed mail is excluded — rows here failed neither DMARC nor the internal-spoof check, so the domain's history really is this sender's. Likely FP — consider releasing or adding an allowlist policy.
No anomalies detected in the selected period.
A3 — Confirmed False Positives. Messages explicitly marked FP by an admin. Look for patterns in sender/reason and tighten filtering rules or domain policies.
No anomalies detected in the selected period.
A4 — Spoofing via Learning. From header impersonates one of your own domains. Delivered because learning mode is active — disabling learning mode will start quarantining these automatically.
No anomalies detected in the selected period.
A5 — Score Spike. Clean-history domain produced a sudden high-score message. Consistent with compromised account or targeted attack leveraging trust. Consider a temporary blocklist policy.
No anomalies detected in the selected period.
A6 — Retroactive Threat. Domain sent clean mail (5+ deliveries) then later sent PHISHING / MALWARE. Earlier deliveries may be part of a trust-building campaign — review older messages from these senders.
No anomalies detected in the selected period.
A7 — Zero-Threat Quarantine. Quarantined despite the sender domain having only clean history (2+ deliveries, 0 bad). Spoofed mail is excluded — rows here failed neither DMARC nor the internal-spoof check, so the clean history really is this sender's. Strong FP signal — consider an allowlist policy.
No anomalies detected in the selected period.
A8 — Repeated FP Domain. Same domain marked FP 2+ times. Systemic over-scoring — review rules / weights or add a domain policy.
No anomalies detected in the selected period.
A9 — DMARC Pass Quarantined. DMARC=PASS + Prior Good ≥ 5 vs. Status=QUAR. Strong FP candidates. Inspect Quarantine Reason for the rule that fired and consider an allowlist or rule tune.
No anomalies detected in the selected period.
A10 — Near-Miss + Risk. Score in suspicious zone (between low/high thresholds) AND had a young URL domain (<30d) or an attachment. Consider tightening URL age penalties or attachment rules.
No anomalies detected in the selected period.
A11 — Now-Blocklisted. Delivered from a domain that now carries an active blocklist policy. Review earlier deliveries from these senders for missed threats.
No anomalies detected in the selected period.
A12 — New Domain Threat. New domain delivered first, then later sent PHISHING / MALWARE. Slow trust-building pattern — review prior deliveries from these senders.
No anomalies detected in the selected period.
AI & Automated Actions
AI calls: 261 Tokens in/out: 1,009,055 / 32,331 Cost: $0.9022 (last 30 days, tenant-wide)
Created Action Reason Subject Verdict OK Detail
2026-10-06 18:24 Auto-classify Quarantine Triage Your delivery could not be completed true_positive 96%
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 17:10 Auto-classify Quarantine Triage Tender pricing schedule true_positive 97%
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-06 15:47 Auto-classify Quarantine Triage Your delivery could not be completed true_positive 96%
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 15:30 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 84%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-06 15:13 Auto-classify Quarantine Triage Remittance advice 08/2026 true_positive 88%
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-06 15:02 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 88%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-06 13:34 Auto-classify Quarantine Triage Quick favour true_positive 90%
Payment fraud: gift-card request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-06 13:32 Auto-classify Quarantine Triage Are you at your desk? true_positive 88%
Payment fraud: executive impersonation, urgent transfer. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-06 11:53 Auto-classify Quarantine Triage Accounts shared 'Remittance advice' with you true_positive 93%
Credential harvesting: fake document share. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 11:49 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 85%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 11:39 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 93%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-06 08:12 Auto-classify Quarantine Triage RE: Invoice 22191 — updated banking details true_positive 89%
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-06 07:43 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 84%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 06:03 Auto-classify Quarantine Triage Ashwin shared 'Remittance advice' with you true_positive 96%
Credential harvesting: fake document share. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-06 02:32 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 86%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-05 23:35 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 88%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-05 19:50 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 89%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-05 16:14 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 87%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-05 14:50 Auto-classify Quarantine Triage Action required: re-enrol your payslip access true_positive 86%
Quishing: QR code resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-05 14:41 Auto-classify Quarantine Triage Change of banking details for my salary true_positive 95%
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-05 12:30 Auto-classify Quarantine Triage Remittance advice 08/2026 true_positive 93%
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-05 12:00 Auto-classify Quarantine Triage RE: Invoice 22520 — updated banking details true_positive 86%
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-05 11:46 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 96%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-05 10:15 Auto-classify Quarantine Triage Payment run — hold the Vaalkop invoice true_positive 88%
Lookalike domain carrying a director's name. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-05 10:00 Auto-classify Quarantine Triage RE: Invoice 22583 — updated banking details true_positive 86%
Payment fraud: banking-change claim inside an existing thread. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-05 07:50 Auto-classify Quarantine Triage Tender pricing schedule true_positive 97%
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-05 03:31 Auto-classify Quarantine Triage Tender pricing schedule true_positive 87%
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-04 16:52 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 91%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-04 16:42 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 90%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-04 13:58 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 95%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-04 13:10 Auto-classify Quarantine Triage Tender pricing schedule true_positive 96%
Attachment content does not match its extension. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-03 02:08 Auto-classify Quarantine Triage Your password expires today true_positive 88%
Credential harvesting: password-expiry lure. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-02 22:17 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 89%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-02 18:26 Auto-classify Quarantine Triage Your delivery could not be completed true_positive 88%
Redirect chain resolves to an unrelated host. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-02 17:09 Auto-classify Quarantine Triage Remittance advice 08/2026 true_positive 97%
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-02 16:35 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 87%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-02 15:38 Auto-classify Quarantine Triage Payment run — hold the Vaalkop invoice true_positive 88%
Lookalike domain carrying a director's name. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-02 14:49 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 97%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-02 12:38 Auto-classify Quarantine Triage Statement of account — 45 days overdue true_positive 95%
Payment portal link inside the attached document. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-02 08:31 Auto-classify Quarantine Triage Scanned document from the finance copier true_positive 94%
Antivirus detection in attachment. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-02 05:37 Auto-classify Quarantine Triage Are you at your desk? true_positive 88%
Payment fraud: executive impersonation, urgent transfer. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-02 00:51 Auto-classify Quarantine Triage Change of banking details for my salary true_positive 96%
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-01 19:05 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 94%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-01 17:53 Auto-classify Quarantine Triage Change of banking details for my salary true_positive 92%
Payment fraud: payroll diversion request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
2026-10-01 16:46 Auto-classify Quarantine Triage Remittance advice 08/2026 true_positive 92%
Macro-enabled document with content-enable coaching. The attachment is detected by the scanner. This is not a judgement call and the message should not be released without a specific reason to believe the detection is wrong.
2026-10-01 16:32 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 90%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-01 14:12 Auto-classify Quarantine Triage Unusual activity on your business account true_positive 84%
Brand impersonation: Karoo Mutual Bank. The link does not belong to the organisation the message claims to be from, and the page behind it asks for credentials that the real service would never request by email.
2026-10-01 12:50 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 95%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-01 11:26 Auto-classify Quarantine Triage Final demand: outstanding VAT201 submission true_positive 92%
Authority impersonation: revenue service. The identity asserted in the From header is not one this connection can support. Nothing else in the message explains the discrepancy.
2026-10-01 09:38 Auto-classify Quarantine Triage Quick favour true_positive 93%
Payment fraud: gift-card request. The request is for money or for a change to where money goes, it arrives outside the normal channel, and it discourages the one step that would catch it — picking up the phone. Verify out of band before anything is paid.
Loading review queue…
Filtering Rules
Priority Category Name Conditions Actions Exceptions Status Triggers Last Triggered
10 security Block executable attachments 1 1 — Enabled 0 1 month ago
15 business Allow the audit firm during year end 1 1 — Disabled 0 Never
20 payment-fraud Hold banking-change claims from outside the supplier list 2 1 — Enabled 0 1 month ago
30 phishing Hold password-reset lures 1 1 — Enabled 0 1 month ago
40 security Quarantine macro-enabled documents 1 1 — Enabled 0 3 weeks ago
60 hygiene Tag newsletters 1 1 — Enabled 0 3 weeks ago
Filter Lists

Named sets of addresses, domains or filename patterns that this tenant's rules reference with the is in list / is not in list conditions — so a long allowlist is entered once instead of retyped into every rule.

Name Type Entries Used by rules Description Actions
Approved suppliers DOMAIN 11 1 Domains we buy from. Referenced by the supplier-invoice rule. Open
Finance team EMAIL 5 0 Mailboxes that can authorise payment. Open
Mail from these senders is not scanned. No URL or attachment check, no virus scan, no impersonation or payment-fraud check, no AI review — it is logged and delivered. Use it for senders you trust completely, and remember a trusted mailbox that gets compromised is the one attackers want most.
Bypassed Senders (1)
Sender Type Authentication Status Added Note
noreply@karoomutual.example EMAIL Required Active nomsa.dlamini@sablemere.example
2026-09-09
Bank statement notifications. DMARC must pass for this to apply.
Tenant Users
Email Name Role Status
craig.bester@sablemere.example Craig Bester TENANT_VIEWER Active
lerato.molefe@sablemere.example Lerato Molefe TENANT_VIEWER Active
pieter.vanwyk@sablemere.example Pieter van Wyk TENANT_MANAGER Active
nomsa.dlamini@sablemere.example Nomsa Dlamini TENANT_ADMIN Active
Domain Ratings (0 domains) — showing most recent 0 of 32 (type a domain and press Enter to search all)
No domains found

Sender domains will appear here as emails are processed

Rating Legend
Reputation Score:
  • ≥ 0 = Good reputation
  • < 0 = Bad reputation
  • +0.1 per delivered
  • -1.0 per phishing/malware quarantine
  • -0.1 per other quarantine
Final Score:
  • > 0 = Trusted
  • < 0 = High Risk
Row Highlighting:
  • Green = Allow-listed domain
  • Red = Blocked domain
  • Allow = Add to allow list
  • Block = Add to block list
Platform Policies
Configure trust policies for common email platforms
Platform Policy Type Score Adjustment Created By Created At
No platform policies configured.
Allow List

Trusted sender domains or specific addresses receive a positive score adjustment (trust boost). Email-address entries override domain-level policies.

Domain / Email Score Status Actions
capereach.example
Established supplier, verified by Finance.
+15 Active
coastal-clearing.example
Established supplier, verified by Finance.
+15 Active
halberd-eng.example
Established supplier, verified by Finance.
+15 Active
karoomutual.example
Established supplier, verified by Finance.
+15 Active
northgate-office.example
Established supplier, verified by Finance.
+15 Active
orbitfuel.example
Established supplier, verified by Finance.
+15 Active
Block List

Blocked sender domains or specific addresses receive a negative score adjustment (distrust). Email-address entries override domain-level policies.

Domain / Email Score Status Actions
coastal-c1earing.example
Used in an impersonation attempt against this tenant.
-25 Active
karoomutual-secure.example
Used in an impersonation attempt against this tenant.
-25 Active
ms-account-verify.example
Used in an impersonation attempt against this tenant.
-25 Active
vaalkop-stee1.example
Used in an impersonation attempt against this tenant.
-25 Active
Loading recipients…
Loading threats…
Protect a person's name against display-name spoofing. Mail whose From name matches a VIP (first + last) but is sent from any other address is flagged Impersonation and held. Seed execs & finance first — very common names can flag a legitimate same-name outsider.
Protected VIPs (3)
Name Addresses (primary + alternates they send from) Status
Craig Bester
craig.bester@sablemere.example
Active
Nomsa Dlamini
nomsa.dlamini@sablemere.example
n.dlamini@sablemere-board.example
Active
Pieter van Wyk
pieter.vanwyk@sablemere.example
Active
Domains exempt from VIP checks (0)

Mail from these domains keeps its VIP name check off — so “Jane Smith via Adobe Acrobat Sign” is not held as impersonation. Applies only when SPF, DKIM and DMARC all pass and the sender is not spoofing one of your own domains; a listed domain that fails authentication is still held, and the refusal is logged. Everything else about the message is still scanned and scored. Exact domain only — eu1.adobesign.com needs its own entry. Consumer webmail (gmail.com, outlook.com…) cannot be exempted.

No exempt domains. Every sender is checked against your VIP names.

Tenant Configuration

Tenant ID

Name *

Protected Domain *

Downstream MX Host *

Downstream Provider

Business Context (for AI)

Created: 2026-08-22 12:26
Updated: 2026-09-09 17:31

DNS Configuration

DNS Error

DNS Protocol

Threat Intelligence DNS Servers

Set a tenant-specific resolver above to enable this.

Status: DNS error detected

Domain does not exist


Required MX record:

TypeHostValuePriority
MX sablemere.example demo.cyberframe.co.za 0

Feature Toggles


Real quarantine for these mailboxes even while the tenant is in Learning Mode. Pick from the recipient list or type a new address. Applies only when Learning Mode is on. On a message sent to several recipients, one enforced recipient holds the whole message.

General mail handling

Deterministic rules — no model, no LLM, no per-message cost.

ML risk model — layer 2

The model scores every message. These bars decide what it settles on its own and what it escalates to the LLM. Free per message.
Skip the LLM when the model is this sure (%)
threat
spam
legit
Blank = always ask the LLM. Example: threat 95 means no LLM call on mail the model is 95%+ sure is a threat.
Anything worse than this stays held for the LLM instead of going to Junk. Use the on-screen sign, e.g. -30. Blank = no limit.
Worse than this (UI sign), quarantine is final — no AI review. Empty = 2× the quarantine threshold.
Which LLM checks may be skipped

How the LLM is used

LLM adjudication — layer 3

Consulted only where the score and the model disagree, or the model is unsure. Every call costs money.
No AI activity recorded for this tenant yet.

Confidence Threshold (%)

Scoring & Reputation

Protection Level

Sets thresholds, first-contact penalty, URL age penalty, invalid-recipient penalty. Existing values stay until you change this dropdown.

Spam Score Thresholds

Spam Classification

Quarantine Threshold

Invalid Recipient Penalty

Reputation Score Adjustments

Good (per delivered)

Bad (per quarantined)

Phishing/Malware Multiplier

URL Domain Age Penalties

Very New (< 30 days)

New (30-89 days)

Trusted Document Hosts

Own SharePoint / OneDrive / file-server hostnames, comma or newline separated. A pasted URL is accepted. Leave empty to trust nothing extra. A bare sharepoint.com is refused — it would trust every Microsoft 365 tenant. A personal OneDrive is shared by every Hotmail user, so it needs the owner path: d.docs.live.net/<owner-id> (copy it from the link in the held message). Remote macro templates (attachedTemplate) are never exempted by this list.

Retention

Email Body Retention

Gateway Actions per Threat Type

Loading...

Loading threat policies...

Danger Zone

Irreversible actions

Delete Tenant

Permanently delete this tenant and all associated data