Catch the domain that is one character away from your vendor.
Domain Intelligence is the first line of the VeridLock risk engine. It decomposes every counterparty address and tests the domain against a battery of impersonation heuristics — entirely offline, with no message content leaving your tenant.
Confusable characters are normalised and the result is edit-distance matched against global brands and your own trusted vendors.
Punycode and mixed-script domains are decoded and flagged before a human ever has to spot the difference.
A domain your organization has registered as trusted scores zero. Everything else must earn its way through.
Every outbound and inbound address is reduced to its registrable domain, then run through eight independent checks. Each check is additive: a clean domain accumulates nothing, so a genuine counterparty is never penalised for the checks that exist.
Gmail, Outlook, Yahoo and their peers are recognised as legitimate mail providers — but recognition is deliberately not the same as trust. Trusting a public provider at the domain level would trust every attacker who can open a free mailbox there.
Instead, VeridLock proceeds to evaluate the exact address. Only a specific verified contact at a public provider is treated as trusted, and that trust never spreads to the rest of the domain.
When a domain trips a heuristic, the finding is written to your organization's flagged-domain register with its severity. The next time anyone in your organization addresses that domain, they are warned before composing — not after sending.
The address is split into local part, domain and TLD, and normalised.
Blocklist, trust list and verified-recipient lookups run first and can end scoring immediately.
Eight impersonation heuristics run against the domain, each contributing to the score.
Positive findings are written to the flagged-domain register for future warnings.
The outcome
A domain that is not registered in your Trust Center is treated as high risk on its own, which forces recipient verification before anything sensitive can leave.
Set up your organization in minutes — no inbound migration required.