VeridLock
The protection pipeline

From an address in a compose box to a decision you can defend.

Every protected send runs through five inspection stages before anything leaves your organization. Each stage answers a different question, and each records its answer.

1

Stage 1 — Domain Recognition & Typo Guard

Is this address even what the sender meant to type?

Email Provider Type
The domain is matched against a database of known public providers — Gmail, Yahoo, Outlook, ProtonMail, iCloud — to establish whether this is a public mailbox or a corporate domain. Recognition is recorded, but it is never treated as trust.
Domain Similarity Check
Confusable characters are normalised and the result is edit-distance matched against global brands and your organization's own client list, catching both deliberate typosquats and accidental slips.
2

Stage 2 — Organization History & Trust Policy

Have we ever done business with this counterparty?

In Trust List
The address and its domain are cross-referenced against your organization's registered trusted domains and verified recipients. Absence is reported as verification required, not as a failure.
Previous Communication
Communication history across your whole organization is queried to establish whether anyone has corresponded with this address or domain before. A first contact is flagged as such.
3

Stage 3 — DNS Infrastructure & Deliverability

Can this domain physically receive mail, and how long has it existed?

MX Records
A DNS lookup confirms whether active mail exchangers are published for the domain. A domain with no MX records cannot receive mail, which is a meaningful tell.
Domain Age
Registration data is queried to establish how recently the domain was created. Domains under thirty days old are heavily associated with phishing and impersonation. Where the data is privacy-protected or throttled, the result is reported as unknown.
4

Stage 4 — Security & Authentication Protocols

Does this domain defend itself against being spoofed?

SPF
DNS TXT records are inspected for a sender policy specifying which servers may send on the domain's behalf.
DMARC
The domain's DMARC policy is retrieved to establish whether it enforces alignment and reporting, and at what strength.
Domain Reputation
Threat intelligence sources and internal interaction metrics are consulted. A domain with no record is reported as unverified — which is distinct from clean.
5

Stage 5 — Decision & Verification

Given everything above, what has to happen before this sends?

Flag aggregation
Every finding is combined into a score, a risk level, a decision and a confidence figure reflecting how many independent signals corroborated each other.
Forced prompts
Where critical flags are present — not in the trust list, no prior communication, unverified reputation — the send is intercepted and a verification prompt is rendered before dispatch is possible.

What the decision can be

Four outcomes, each mapping to an explicit request state.

Allow

Cleared to send — but only for a counterparty already registered in your trust list. A person still presses send.

Manager approval

Held until a manager authorizes it. Authorization happens in the VeridLock mobile app.

Recipient verification

Held until the recipient confirms a one-time code over SMS, WhatsApp or email.

Quarantine

Blocked outright. The message does not become sendable from this request.

The trust gate

A low score alone can never release a message to a counterparty your organization has not registered. Unknown counterparties are forced onto a human path — recipient verification, manager authorization, or both — whatever the engine scored. This is the single rule that stops a quiet message to an unfamiliar address from slipping out.

Run it against your own traffic.

Start free, then upgrade when you need verification and approvals.