CloudCastle Email Security

Every message gets a second opinion

CloudCastle checks who sent a message, what it asks you to do, where its links go and what its files contain. It catches fake-boss scams, phishing, spam and malware before they can hurt you.

Six coordinated engines

The short version

What Email Security does for you

Every new message gets several focused checks before you trust the sender, click a link or open a file.

Identity

Catches impersonation

CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.

Intent

Understands the request

It looks for password theft, fake invoices, payroll changes, gift-card scams and other urgent requests designed to pressure people.

Content

Checks links and files

Websites are checked again when clicked, while attachments are scanned and suspicious files can be opened safely away from your computer.

Best of both worlds

Perception Point speed. Proofpoint depth. Built in house.

CloudCastle combines the architectural strengths associated with both approaches instead of reselling either product.

Perception Point-style inline analysis

Understand the message immediately

  • ONNX language models classify BEC and phishing intent
  • Computer vision recognizes copied logos, login forms and QR-code lures
  • Header alignment exposes display-name, Reply-To and envelope deception
  • Independent engines run concurrently under individual time budgets
Proofpoint-style defense in depth

Keep checking after the first scan

  • Rewritten links are checked again at the exact moment of the click
  • YARA and ClamAV inspect files locally before delivery
  • Suspicious files can be detonated in a CAPEv2 sandbox
  • Reputation feeds, DNS blocklists and lookalike-domain detection corroborate risk

Perception Point and Proofpoint are referenced only to explain the design pattern. CloudCastle Email Security is our independently built engine and is not affiliated with either vendor.

The scanning pipeline

Six views of the same email. One explainable verdict.

A slow or unavailable engine cannot erase the healthy findings from the others. Each layer returns evidence, status and latency to the final report.

Layer 1

Message reputation

Rspamd scores spam, sender authentication and known message patterns. CloudCastle adds its own header-alignment and VIP-identity checks even if Rspamd is unavailable.

Layer 2

Language intelligence

An ONNX intent model classifies credential phishing, invoice fraud, payroll diversion, gift-card scams, extortion and malware lures. Deterministic context signals corroborate the model.

Layer 2

Computer vision

OpenCV perceptual hashes compare embedded images with a brand-logo database. Rectangle density identifies rendered login forms; QR detection catches quishing.

Layer 3

URL defense

Threat feeds, Spamhaus DBL, SURBL and URIBL checks are combined with homoglyph and edit-distance detection for typosquatted domains. Every rewritten link is signed, scoped and expiring.

Layer 3

Attachment analysis

YARA and ClamAV scan attachments and bounded archive contents. Macro-capable, executable or convicted files become candidates for deeper analysis instead of delaying every clean message.

Layer 4

Sandbox and aggregate

CAPEv2 can detonate selected candidates and return signatures, dropped files, network activity and IOCs. The weighted aggregator then records the evidence behind benign, suspicious or malicious.

Business email compromise

BEC has no malware. We still see it.

A forged request from the boss can be technically clean: no malicious file, no bad link, and valid SPF for the attacker’s own domain. CloudCastle looks at identity, intent and context together.

  • VIP impersonation: a protected executive or help-desk name must come from its registered domain, including common homoglyph tricks.
  • Routing deception: From, Reply-To, Return-Path and SMTP envelope domains are compared independently.
  • Financial intent: invoice, wire-transfer, payroll and banking-change language is classified separately from ordinary spam.
  • Correlated evidence: urgency, authority claims, credential requests and domain mismatch must reinforce one another; one keyword cannot convict a message.
A suspicious sign-in request and impersonated identity being detected

Threat coverage

More than a spam score

Each attack class is handled by evidence designed for that attack, not by one opaque number.

Phishing

Credential theft

Language models identify account-verification and password-reset lures while URL and vision layers inspect the destination, copied branding and rendered login form.

Spam

Bulk and nuisance mail

Rspamd’s message signals, sender authentication and reputation data separate ordinary junk from targeted social engineering without treating every marketing email as malware.

Quishing

QR-code attacks

OpenCV extracts QR codes from embedded images so an attacker cannot bypass ordinary link inspection by moving the destination into a picture.

Malware

Weaponized files

YARA, ClamAV, bounded archive expansion and selective CAPEv2 detonation inspect the file the recipient actually received, including nested message attachments.

URL defense

Late-armed websites

A link that was safe at delivery is checked again at click time. Expiring HMAC tokens bind the original URL to its tenant and, where available, its intended recipient.

Brand abuse

Lookalikes and copied logos

Homoglyph folding, transposition-aware edit distance and perceptual logo matching expose domains and images built to look almost legitimate.

Deployment

Protect a domain, or connect personal email

One CloudCastle engine, three safe deployment paths. Consumer accounts need no custom domain or DNS change.

Retail connector

50+ personal-email domains

Connect Microsoft personal, Comcast/Xfinity, Spectrum, AT&T, Cox, CenturyLink, Optimum, Verizon, Frontier, EarthLink, Windstream, Mediacom, Juno, NetZero, Gmail, Yahoo, AOL, iCloud, Fastmail, or Zoho accounts from the customer portal. CloudCastle detects the provider, verifies access, scans only new mail, and isolates spam and threats without a DNS change.

Microsoft uses secure OAuth sign-in. Providers with app passwords or secure mail keys use those revocable credentials; legacy POP-only mailboxes use CloudCastle’s encrypted hold-and-release vault.

Mailbox mode

One business inbox

CloudCastle watches a selected inbox over encrypted IMAP, scans new mail, and moves malicious messages into a dedicated quarantine folder. Each credential protects one mailbox, so coverage stays explicit.

Useful for providers that must remain authoritative for the domain’s MX, or for a controlled first deployment.

Gateway mode

Domain-wide protection

Your domain’s MX sends inbound mail through CloudCastle before it reaches the existing mail host. This covers every mailbox on the routed domain and supports pre-queue rejection or safe delivery with mitigation.

Recommended only after provider discovery confirms that external inbound routing will not disable outbound mail.

Put CloudCastle between you and the next bad email

Customers across more than 50 personal-email domains can connect one mailbox in the portal. Business customers can start with one mailbox or map a safe domain-wide route.