Catches impersonation
CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.
CloudCastle Email Security
CloudCastle checks who sent a message, what it asks you to do, where its links go and what its files contain. It catches fake-boss scams, phishing, spam and malware before they can hurt you.
Six coordinated engines
Email verdict
Benign · suspicious · malicious
The short version
Every new message gets several focused checks before you trust the sender, click a link or open a file.
CloudCastle compares the sender name, address and reply path to uncover fake executives, vendors and support teams.
It looks for password theft, fake invoices, payroll changes, gift-card scams and other urgent requests designed to pressure people.
Websites are checked again when clicked, while attachments are scanned and suspicious files can be opened safely away from your computer.
Best of both worlds
CloudCastle combines the architectural strengths associated with both approaches instead of reselling either product.
Perception Point and Proofpoint are referenced only to explain the design pattern. CloudCastle Email Security is our independently built engine and is not affiliated with either vendor.
The scanning pipeline
A slow or unavailable engine cannot erase the healthy findings from the others. Each layer returns evidence, status and latency to the final report.
Rspamd scores spam, sender authentication and known message patterns. CloudCastle adds its own header-alignment and VIP-identity checks even if Rspamd is unavailable.
An ONNX intent model classifies credential phishing, invoice fraud, payroll diversion, gift-card scams, extortion and malware lures. Deterministic context signals corroborate the model.
OpenCV perceptual hashes compare embedded images with a brand-logo database. Rectangle density identifies rendered login forms; QR detection catches quishing.
Threat feeds, Spamhaus DBL, SURBL and URIBL checks are combined with homoglyph and edit-distance detection for typosquatted domains. Every rewritten link is signed, scoped and expiring.
YARA and ClamAV scan attachments and bounded archive contents. Macro-capable, executable or convicted files become candidates for deeper analysis instead of delaying every clean message.
CAPEv2 can detonate selected candidates and return signatures, dropped files, network activity and IOCs. The weighted aggregator then records the evidence behind benign, suspicious or malicious.
Business email compromise
A forged request from the boss can be technically clean: no malicious file, no bad link, and valid SPF for the attacker’s own domain. CloudCastle looks at identity, intent and context together.
Threat coverage
Each attack class is handled by evidence designed for that attack, not by one opaque number.
Language models identify account-verification and password-reset lures while URL and vision layers inspect the destination, copied branding and rendered login form.
Rspamd’s message signals, sender authentication and reputation data separate ordinary junk from targeted social engineering without treating every marketing email as malware.
OpenCV extracts QR codes from embedded images so an attacker cannot bypass ordinary link inspection by moving the destination into a picture.
YARA, ClamAV, bounded archive expansion and selective CAPEv2 detonation inspect the file the recipient actually received, including nested message attachments.
A link that was safe at delivery is checked again at click time. Expiring HMAC tokens bind the original URL to its tenant and, where available, its intended recipient.
Homoglyph folding, transposition-aware edit distance and perceptual logo matching expose domains and images built to look almost legitimate.
Deployment
One CloudCastle engine, three safe deployment paths. Consumer accounts need no custom domain or DNS change.
Connect Microsoft personal, Comcast/Xfinity, Spectrum, AT&T, Cox, CenturyLink, Optimum, Verizon, Frontier, EarthLink, Windstream, Mediacom, Juno, NetZero, Gmail, Yahoo, AOL, iCloud, Fastmail, or Zoho accounts from the customer portal. CloudCastle detects the provider, verifies access, scans only new mail, and isolates spam and threats without a DNS change.
Microsoft uses secure OAuth sign-in. Providers with app passwords or secure mail keys use those revocable credentials; legacy POP-only mailboxes use CloudCastle’s encrypted hold-and-release vault.
CloudCastle watches a selected inbox over encrypted IMAP, scans new mail, and moves malicious messages into a dedicated quarantine folder. Each credential protects one mailbox, so coverage stays explicit.
Useful for providers that must remain authoritative for the domain’s MX, or for a controlled first deployment.
Your domain’s MX sends inbound mail through CloudCastle before it reaches the existing mail host. This covers every mailbox on the routed domain and supports pre-queue rejection or safe delivery with mitigation.
Recommended only after provider discovery confirms that external inbound routing will not disable outbound mail.
Customers across more than 50 personal-email domains can connect one mailbox in the portal. Business customers can start with one mailbox or map a safe domain-wide route.