VeridLock
Risk signal

Domain Intelligence

Catch the domain that is one character away from your vendor.

Domain Intelligence is the first line of the VeridLock risk engine. It decomposes every counterparty address and tests the domain against a battery of impersonation heuristics — entirely offline, with no message content leaving your tenant.

Algorithmic typosquatting

Confusable characters are normalised and the result is edit-distance matched against global brands and your own trusted vendors.

Homograph & IDN defence

Punycode and mixed-script domains are decoded and flagged before a human ever has to spot the difference.

Trust-aware scoring

A domain your organization has registered as trusted scores zero. Everything else must earn its way through.

What it inspects

Every outbound and inbound address is reduced to its registrable domain, then run through eight independent checks. Each check is additive: a clean domain accumulates nothing, so a genuine counterparty is never penalised for the checks that exist.

  • Blocklist match — an instant maximum score for domains your organization has explicitly banned.
  • Trust list match — a registered trusted domain short-circuits scoring at zero.
  • Typosquatting — confusable-character de-obfuscation (rn→m, 1→l, 0→o) followed by Levenshtein distance against a built-in brand list.
  • Homograph / IDN — punycode expansion and non-ASCII script detection.
  • Lookalike of a trusted vendor — the same distance test run against your own Trust Center entries.
  • Brand-as-subdomain abuse — catching paypal.secure-billing.tld and its family.
  • Disposable and high-risk TLDs — throwaway providers and TLDs with disproportionate abuse rates.
  • Entropy / DGA — randomly generated labels typical of automated phishing infrastructure.

Public providers are recognised, not trusted

Gmail, Outlook, Yahoo and their peers are recognised as legitimate mail providers — but recognition is deliberately not the same as trust. Trusting a public provider at the domain level would trust every attacker who can open a free mailbox there.

Instead, VeridLock proceeds to evaluate the exact address. Only a specific verified contact at a public provider is treated as trusted, and that trust never spreads to the rest of the domain.

Repeat offenders are remembered

When a domain trips a heuristic, the finding is written to your organization's flagged-domain register with its severity. The next time anyone in your organization addresses that domain, they are warned before composing — not after sending.

How it runs

01

Decompose

The address is split into local part, domain and TLD, and normalised.

02

Match

Blocklist, trust list and verified-recipient lookups run first and can end scoring immediately.

03

Analyse

Eight impersonation heuristics run against the domain, each contributing to the score.

04

Record

Positive findings are written to the flagged-domain register for future warnings.

The outcome

A domain that is not registered in your Trust Center is treated as high risk on its own, which forces recipient verification before anything sensitive can leave.

Related services

Protect your outbound communications today.

Set up your organization in minutes — no inbound migration required.