
Every suspect link opened in an isolated browser, before your users
A link cannot be judged by its name. SecuBlocker opens the URL in your place, outside your network, and the message waits for that verdict.
Request a demoPhishing kits are hosted by respectable people
Google Sites, Vercel, Framer, Wix, Weebly, Webflow, Netlify, pages.dev, Jimdo, URL shorteners. These are legitimate, widely used platforms with excellent reputations — which is precisely why fraudulent pages are placed on them.
Such pages often live only a few hours, move to a new address with every campaign, and appear on no blocklist by the time the message arrives. The domain is clean and the certificate is valid: a filter querying a reputation database finds nothing to object to, and the message goes out for delivery.
So we hold the message for an in-depth analysis
SecuBlocker opens the URL in your place. Every link pointing to a watched platform is rendered in an isolated browser (Virtual Browser Isolation) outside your network: the page runs with its JavaScript, and its code, redirects are followed to the final destination, and the resulting screenshot is analysed. Until that verdict exists, the message is not delivered.
The message is held
By a temporary refusal, the kind every mail server knows how to handle. The sender retries on its own, nothing is lost, and its infrastructure is unaffected.
A browser opens the page
Not a database lookup: on machines of our own, kept apart from everything else, a browser runs the page with its JavaScript, and its code, follows redirects to the final destination, and the resulting screenshot is analysed.
The message goes on, or not
On the next attempt the verdict exists. The message is delivered, or its handling takes account of what was found.
Without that wait, an unvalidated URL added too little weight to reach the blocking threshold: the message was delivered before the page had been looked at. That is the gap this closes.
Two levels, because a host is not guilty
The verdict is issued at two levels: the host domain, and the exact address of the page.
Condemning Netlify because a fraudulent page is hosted there would mean discarding mail from everyone who uses it honestly. The finer level targets the page, not the platform.
After-the-fact discovery and remediation
A URL can turn malicious later — the page was empty when analysed, armed the next day. Every analysed link therefore leaves a usable trail.
- The messages that carried that URL, and what became of each one
- The addresses in your domain that received them
- The clicks observed, with the country they came from, where ProtectLink is active
Enough to warn your users yourself, by name, rather than sending a general notice to the whole company.
What we will not tell you
A URL that is “not allowed” is not a URL that was “blocked”, and we refuse to conflate the two.
An unfavourable verdict weighs on how a message is handled; it does not decide its fate alone. What actually became of a message is read from its delivery status, message by message — not from a promise. We would rather give you the second.
The other half of the subject
This works on arrival, before the message reaches the mailbox. ProtectLink works at click time, sometimes weeks later, when a page that has since turned malicious is finally opened.
Two moments, two distinct risks. Neither covers the other.
See ProtectLinkReady to test e-securemail on your current mail platform?
Our experts review your current setup and run a demonstration tailored to your mail platform.