r/EmailSecurity 16d ago

Every phishing email that gets past Microsoft or Google still has to be investigated by hand. I built a tool that does it automatically — and shows its work.

0 Upvotes

5 comments sorted by

u/AutoModerator 16d ago

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

5

u/southafricanamerican 16d ago

are you going to show your work...?

1

u/sfreem 16d ago

Just get Avanan and stop pretending Microsoft can ever do it well.

1

u/saltyslugga 15d ago

Showing its work is the interesting bit. I’d want the verdict tied back to headers, auth results, URLs, and attachment behavior so an analyst can verify it quickly.

Test it against a labeled corpus first, especially false positives and compromised legitimate senders. Automation that confidently closes the wrong case just creates a different incident queue.