deepmailscan

When AI and behavioural analysis strengthen your security

Sender, reputation, keywords: that is what a spam filter looks at, and exactly what a modern attack knows how to bypass effortlessly. The message comes from a clean domain, the certificate is valid, and the trap page was created that same morning.

Request a demo

What conventional sorting cannot see

A filter that queries reputation databases can say nothing about an address with no history. And that is precisely what the attacker manufactures: something new, clean and disposable.

In-depth analysis means no longer trusting what a message declares, but opening what it carries — the files, the links, the turn of phrase. That is what the expression “deep mail scan” covers, and what e-securemail does on four fronts.

The four stages of the DeepMailScan analysis

Each answers a different way of slipping a threat through. None replaces the others.

01

Attachment analysis

Files are opened, not merely listed: an extension can be forged, so the analysis works on the real content. Images are turned into text, because an instruction written inside an image escapes any automated reading — and QR codes are extracted, then analysed as links.

02

Sandboxing

Whatever has to be opened to be understood is opened at our end, never at yours. Machines of our own, kept apart from everything else, run what the message carries and watch what happens. The trap springs there, far from your network. Behavioural analysis of attachments comes on top, as an option.

03

URL inspection

A link cannot be judged by its name. SecuBlocker opens the URL in your place: the page is rendered in an isolated browser outside your network, its JavaScript runs, redirects are followed to the real destination, and the resulting capture is analysed. The message waits for that verdict. ProtectLink takes over at click time, sometimes weeks later, when a page that has since turned malicious is finally opened.

04

AI-powered behavioural analysis

Some attacks are entirely in order: authenticated sender, no suspect word, not one attachment. Nothing to hold against the message — everything to hold against the way it is sent. A domain never seen here that reaches dozens of organisations within minutes, a campaign spread across twin domains to stay under the thresholds, an address that had never written to anyone suddenly contacting hundreds of recipients: these are behaviours, not contents. In case of doubt the message is held long enough to decide — a legitimate sender is delayed by a few minutes.

More complete and more innovative, natively

The four layers of analysis in DeepMailScan are only a small part of the technologies e-securemail brings to email cybersecurity.

It also covers the deliverability, resilience, regulatory compliance and governance of your messaging.

All of it fully sovereign, and always with no surcharges, no options and no higher plan.

Take a look at our comparison, drawn from freely available information.

See the comparison

And what remains of it afterwards

A page can look harmless on the day it is analysed and carry an attack the next. Every link examined therefore leaves a usable trail in the console.

  • The messages that carried that URL, and what became of each one
  • The addresses in your domain that received them
  • The clicks observed, with the country they came from

Enough to warn the people concerned by name, rather than sending a general alert to the whole company.

Ready to test e-securemail on your current mail platform?

Our experts review your current setup and run a demonstration tailored to your mail platform.