EU-built email identity verification for Microsoft 365
Safemarker is an EU-based email identity solution for Microsoft 365. It confirms who is really behind every email your team receives, the person and not just the address, and puts a clear answer on the message before anyone acts on it.
Re: Q3 supplier settlement — final schedule
Attaching the agreed schedule. The remaining balance of €486,200 goes out on the existing account, Thursday as planned.
How the attack happens
The email can come from a real colleague, from their real address, inside an existing thread. There may be no suspicious link, attachment or obvious sign of phishing.
Right email address, the usual name, and in the same email thread. Every check passes, because there is nothing wrong with the email or its content.
Four minutes. The email looked exactly like the one the CFO really sent thirty-nine minutes later.
The CFO's mailbox did send it, but from a new device, at an hour the CFO has never worked, asking for money to go somewhere new. Your accounts payable clerk sees a big High Risk label listing all three, before they touch the email. The payment never happens, and nobody had to be a security expert to stop it.
How Safemarker works
Your team keeps working exactly as they do now. Safemarker is not a secure email gateway. It connects to Microsoft 365 through Microsoft's own API, so there is nothing to re-route and nothing to replace.
Every message carries a clear label (Trusted, Caution or High Risk) before anyone opens it, on every device. Open the pane beside it and you get what the label rests on, and what to do next.
Used by everyone with a mailbox
An overview of what came in, what was flagged and why, and where the gaps in coverage are.
Used by whoever owns security
Why your current controls miss it
Most email security looks for known signs of phishing: suspicious links, attachments, sender reputation, known patterns and risky wording. A convincing email from a real, compromised account may contain none of them.
SPF · DKIM · DMARC
They confirm that the email was sent through infrastructure authorised for that domain. A compromised mailbox can still pass these checks.
Does not confirm who is using the account
Your spam and phishing filters
They check links, attachments, reputation and other indicators. An email sent from a real colleague's account may not contain any of them.
Can miss a compromised trusted account
Safemarker
Safemarker compares the message with what is normal for that sender, including device, location, sending behaviour and other identity signals.
Shows an identity verdict on the message
European by default
Safemarker is a Dutch company hosted in the EU. Email data is processed in the EU, and email content is never stored
Safemarker is a Dutch company and runs its infrastructure in the EU. Email data is processed and stored in the EU.
We keep the verdict and the signals behind it, not the message body or attachments.
Safemarker does not send your email content to an LLM or use one to decide the verdict.
Helping users spot risk
Each verdict shows the signals behind it in plain language, so the person reading the email can understand the risk without knowing security.
For years the reasoning behind "this email is dangerous" sat with the security team. Everyone else got a warning banner and learned to click past it. Nobody learned anything.
"Sent from a device this person has never used." "A new inbox rule is hiding the replies." After a few weeks your team recognises the pattern themselves, on their personal email too.
Product tour
Two screens. Only the first one is part of anybody’s working day.
The real mailbox. Not the real person.
Who sent it
The account is confirmed. That does not prove the person typing is Marta.
What we noticed
What you can do
Whoever pays this invoice works in Accounts Payable, not in security. So the label comes first, and everything under it is written in ordinary words.
| Sender | Verdict | Why | Seen |
|---|---|---|---|
Marta Keller marta.keller@northbridge.example |
High Risk | Asks to move money, from a device never used before, at 03:17 | 09:02 |
accounts@vendorbrjdge.example external · never seen before |
High Risk | Address imitates a supplier you actually work with | 08:47 |
Tomas Reiner tomas.reiner@northbridge.example |
Caution | A new browser this morning, never used before | 08:31 |
Ines Halder ines.halder@northbridge.example |
Caution | A new mailbox rule quietly files replies from Finance away | 08:12 |
Priya Raman priya.raman@northbridge.example |
Trusted | Nothing unusual | 08:04 |
Alongside the detection list: a map of who in your organisation is protected and who isn't, the full history behind any one sender, and an audit trail you can hand to an auditor without editing it first.
Who it's for
The person reading the email
The person responsible for security
Common questions
No. There is no MX change, gateway or rerouting. Safemarker runs alongside Microsoft 365.
Under 5 minutes. Safemarker starts building the identity profile as soon as it is connected and can begin checking behaviour almost immediately.
Yes. External senders are checked for impersonation, unusual behaviour, suspicious requests and other risk signals.
Safemarker looks beyond the mailbox itself. A new device, unusual location, abnormal sending time or other changes can raise the risk even when the account is legitimate.
Less than 10 minutes. An admin approves Safemarker in Microsoft 365 and deploys the add-in centrally.
Contact
Tell us how many mailboxes you have and we will show you Safemarker running against real traffic. See it working on your own Microsoft 365 tenant.
Get started
Start with a pilot group and see verdicts the same day. No migration or rerouting. Turn it off at any time and your mail keeps working as before.