VeridLock
The differentiator

Recipient Verification

Confirm the human on the other end, out of band, before you send.

This is the layer no inbound gateway provides. When a send looks risky, VeridLock pauses it and issues a one-time code to the recipient over a channel the attacker does not control — SMS, WhatsApp or email — and the send only proceeds once that code comes back.

Out-of-band by design

The verification travels over a different channel than the email itself, so compromising the mailbox is not enough.

Short-lived codes

Codes expire quickly. An unused code is worthless minutes later, and the request returns to draft for review.

Verified once, trusted after

A recipient who has completed verification and approval can be added to your trust list, so routine correspondence stays frictionless.

Why out-of-band matters

Business email compromise works because the email channel itself looks correct. The domain resolves, the message is well written, the reply address answers. Every check that stays inside email can be satisfied by an attacker who has done their homework.

Verification steps outside that channel entirely. A code delivered to the phone number on the client file cannot be intercepted by someone who has only taken over a mailbox or registered a lookalike domain.

Channels and delivery

SMS and WhatsApp are delivered through a configured provider; email verification and the default evaluation mode use a safe logging channel that issues real codes without dispatching them externally.

Paid channels are entitlement-gated. An organization whose plan does not include SMS or WhatsApp verification silently falls back to the logging channel — the platform never triggers a billable send on behalf of a tenant that has not paid for it.

What happens when a code is not used

A code that expires does not release the send and does not fail silently. The request stays visible in the sender's recent requests as awaiting verification, and the sender can reissue a code, escalate for manager authorization, or cancel and return the message to draft.

How it runs

01

Pause

A risky send is held before dispatch rather than released and regretted.

02

Issue

A one-time code is generated and delivered over the chosen channel.

03

Confirm

The recipient returns the code; the requirement is cleared and the state machine recomputes.

04

Release or escalate

The send proceeds, or continues to manager approval if that is also required.

The outcome

The recipient is confirmed by a person, not by a header — which is the only check that survives a convincing impersonation.

Related services

Protect your outbound communications today.

Set up your organization in minutes — no inbound migration required.