EU-built email identity verification for Microsoft 365

Verify the person behind the email.

Safemarker is an EU-based email identity solution for Microsoft 365. It confirms who is really behind every email your team receives, and puts a clear answer on the message before anyone acts on it.

Set up in 10 minutes
verify / inbound verified
MK
Marta Keller · CFO
marta.keller@northbridge.example

Re: Q3 supplier settlement — final schedule

Attaching the agreed schedule. The remaining balance of €486,200 goes out on the existing account, Thursday as planned.

Trusted Every check passed.
Three real messages
Backed and supported by
YES!Delft Rabobank

How the attack happens

A compromised account can send a convincing confidential request.

The email can come from a real colleague, from their real address, inside an existing thread. There may be no suspicious link, attachment or obvious sign of phishing.

Step 1

Attacker gets access to Sarah's email account

Step 2

Attacker sends an email as Sarah

Step 3 · 09:02

You receive it from Sarah's real email address

09:02

The message arrives

Right email address, the usual name, and in the same email thread. Every check passes, because there is nothing wrong with the email or its content.

09:06

User trusted a malicious message

To the recipient, it is simply another email from Sarah. They read it, reply, click, or act on it the same way they normally would.

Safemarker would flag the 09:02 message.

The CFO's mailbox did send it, but from a new device, at an hour the CFO has never worked, asking for something that doesn't look odd at all for this person. Whoever receives it sees a big High Risk label listing all three, before they touch the email. Nothing gets sent, shared, or approved, and nobody had to be a security expert to stop it.

How Safemarker works

Easy to deploy across your Microsoft 365 email environment.

Your team keeps working exactly as they do now. Safemarker is not a secure email gateway. It connects to Microsoft 365 through Microsoft's own API, so there is nothing to re-route and nothing to replace.

10 minutesto set up the whole organisation
No workflow changefor end users
No gatewayin your mail
Add-in & labels
Outlook with a High Risk label on the message and the Safemarker pane open beside it, listing a new device, an unusual app and a weekend send time.

What your team sees in Outlook

Every message carries a clear label (Trusted, Caution or High Risk) before anyone opens it, on every device. Open the pane beside it and you get what the label rests on, and what to do next.

Used by everyone with a mailbox

Console
The Safemarker admin console Overview tab: messages checked, Caution and High Risk counts, verdicts by hour, mailbox coverage, and a queue of detections needing review.

What your security lead sees

An overview of what came in, what was flagged and why, and where the gaps in coverage are.

Used by whoever owns security

Why your current controls miss it

A real mailbox can still send a fraudulent email.

Most email security looks for known signs of phishing: suspicious links, attachments, sender reputation, known patterns and risky wording. A convincing email from a real, compromised account may contain none of them.

SPF · DKIM · DMARC

Verify the
sending domain

They confirm that the email was sent through infrastructure authorised for that domain. A compromised mailbox can still pass these checks.

Does not confirm who is using the account

Your spam and phishing filters

Look for known signs of malicious email

They check links, attachments, reputation and other indicators. An email sent from a real colleague's account may not contain any of them.

Can miss a compromised trusted account

Safemarker

Checks the identity behind the email

Safemarker compares the message with what is normal for that sender, including device, location, sending behaviour and other identity signals.

Shows an identity verdict on the message

Cross-organizational verification

Verify email between companies.

When both organisations use Safemarker, they can verify who is really behind the email.

Your company On Safemarker
Supplier On Safemarker
Partner On Safemarker

European by default

We never store your email. No AI decides anything.

Safemarker is a Dutch company hosted in the EU. Email data is processed in the EU, and email content is never stored

Hosted in the EU

Safemarker is a Dutch company and runs its infrastructure in the EU. Email data is processed and stored in the EU.

Email content is not stored

We keep the verdict and the signals behind it, not the message body or attachments.

No LLM-based verdicts

Safemarker does not send your email content to an LLM or use one to decide the verdict.

Helping users spot risk

Users see why an email was flagged.

Each verdict shows the signals behind it in plain language, so the person reading the email can understand the risk without knowing security.

Most people have never been told why

For years the reasoning behind "this email is dangerous" sat with the security team. Everyone else got a warning banner and learned to click past it. Nobody learned anything.

The reason is shown directly on the email.

"Sent from a device this person has never used." "A new inbox rule is hiding the replies." After a few weeks your team recognises the pattern themselves, on their personal email too.

Product tour

See Safemarker in action.

Two screens. Only the first one is part of anybody’s working day.

SafemarkerChecked 09:02

High Risk

The real mailbox. Not the real person.

Who sent it

MK
Marta Keller
marta.keller@northbridge.example
Compromised

The account is confirmed. That does not prove the person typing is Marta.

What we noticed

Asks you to move money
And mentions a change of bank details
New device
First message Marta has ever sent from it
Sent outside the usual hours
03:17 where Marta normally works

What you can do

Confirm by phone before paying
Report this to security

Designed for the person taking action.

Whoever pays this invoice works in Accounts Payable, not in security. So the label comes first, and everything under it is written in ordinary words.

  • 1The label comes first. One line at the top. A glance is enough to know how carefully to read the rest.
  • 2The reasons are written for people. "Asks you to move money", not a rule name and a number. Nobody has to be trained to read it.
  • 3It says what to do next. A specific action, matched to what is wrong with this message, rather than a general warning.
  • 4It works even if nobody opens the pane. The label is put on the message itself in Outlook, seconds after it arrives, on every device.

Who it's for

For the person reading the email and the person reviewing it.

The person reading the email

Does not need to be a security expert.

  • Nothing new to learn. The label is on the message they were already reading.
  • No guessing about a lookalike address. The sender status is shown directly on the email.
  • Clear next steps, not a general warning they have learned to click past.

The person responsible for security

Sees exactly why a message was flagged.

  • Every detection shows why it was triggered. Nothing unexplained to defend in a meeting.
  • A full record of the detection. Who sent what, when, from where, and what we decided.
  • Act on the email. Quarantine it, report it, or take the next response directly from the detection.

Common questions

Common questions.

Does Safemarker change our mail flow?

No. There is no MX change, gateway or rerouting. Safemarker runs alongside Microsoft 365.

How long does it take to learn about an identity?

Under 5 minutes. Safemarker starts building the identity profile as soon as it is connected and can begin checking behaviour almost immediately.

Does Safemarker check external senders too?

Yes. External senders are checked for impersonation, unusual behaviour, suspicious requests and other risk signals.

What happens if an account is compromised?

Safemarker looks beyond the mailbox itself. A new device, unusual location, abnormal sending time or other changes can raise the risk even when the account is legitimate.

How long does setup take?

Less than 10 minutes. An admin approves Safemarker in Microsoft 365 and deploys the add-in centrally.

Contact

Talk to us.

Tell us how many mailboxes you have and we will show you Safemarker running against real traffic. See it working on your own Microsoft 365 tenant.

Email hi@safemarker.com We answer the same working day. Demo Book a demo 30 minutes, on your own tenant.
Where we are European Union EU company, EU hosting, EU data protection law.

Get started

Show a clear verdict on every email.

Start with a pilot group and see verdicts the same day. No migration or rerouting. Turn it off at any time and your mail keeps working as before.

01  Approve access 02  Roll out the solution 03  First verdicts the same day
Backed and supported by
YES!Delft Rabobank

Book a demo

See it on your own tenant.

30 minutes, against real traffic. Tell us a little about your organisation and we will reply the same working day to find a time.