Safemarker

How it works

Email security goes beyond the message.

A legitimate email account can still be compromised. Safemarker examines sending behaviour, account activity and email threats to identify suspicious activity that conventional authentication checks may miss.

The findings appear directly in Outlook as a clear security label, Trusted, Caution, High Risk or Unsigned, with supporting evidence and recommended actions.

Understanding sender behaviour

Safemarker compares available account and sending signals against established patterns to identify activity that may indicate account compromise.

SignalWhat Safemarker checksWhy it matters
Device

Previously observed and unfamiliar devices.

An unexpected device may indicate unauthorized access.

Browser & OS

Changes in browser and operating system.

Unfamiliar environments can indicate unusual activity.

Sending application

Email clients and applications used to send messages.

Unexpected applications may indicate account misuse.

Location & network

Sign-in locations, IP addresses and network changes.

Unusual access patterns can indicate compromise.

Sign-in activity

Risky sign-ins and authentication anomalies.

Suspicious authentication events provide additional context.

Sending time

Message timing compared with historical activity.

Unusual sending hours may warrant investigation.

Mailbox rules

Changes to forwarding and inbox rules.

Attackers may use rules to conceal or redirect messages.

Message intent

Sensitive requests involving payments, credentials or access.

High-impact requests require additional scrutiny.

Mailbox type

Shared, individual and automated mailboxes.

Different mailbox types require different behavioural baselines.

Cross-organization verification

Sender verification between participating Safemarker organizations.

Provides additional assurance about the sending account.

Available signals depend on the sender, account access and the connected Microsoft 365 environment. Safemarker identifies suspicious patterns; it cannot establish who physically authored a message or guarantee detection of every compromise.

Threats Safemarker detects

Safemarker combines available account activity, sender behaviour, and email analysis to identify suspicious messages.

Account compromise

Business email compromise

Suspicious activity from legitimate email accounts, including account takeover, supplier compromise, and conversation hijacking.

Account takeover · Supplier compromise · Conversation hijacking

Sender impersonation

Lookalike domains and display names impersonating known contacts or organizations.

Payment fraud

Suspicious requests involving bank details, payment instructions, or payment portals.

Credential phishing

Suspicious sign-in pages delivered through links or QR codes.

Calendar phishing

Malicious links and suspicious organizers in meeting invitations.

Establishing a baseline

Safemarker builds behavioural baselines from available historical activity, including commonly used devices, applications, locations and sending times.

New or unfamiliar senders have limited history. In these cases, Safemarker relies more heavily on available email, domain and authentication signals until sufficient behavioural data is established.

Additional email checks

Alongside account activity, Safemarker examines message-level indicators to identify impersonation, phishing and other email threats.

Domain reputation & impersonation

Checks domain reputation, registration history and similarities to known domains.

Display name verification

Identifies inconsistencies between sender names, email addresses and known contacts.

Email authentication

Evaluates SPF, DKIM and DMARC results. Passing authentication does not establish that an account is uncompromised.

External sender behaviour

Examines sender history, communication frequency and unusual changes in established patterns.

Link analysis

Checks URLs and their destinations for suspicious or malicious activity.

QR code analysis

Extracts and evaluates URLs embedded in QR codes.

Calendar invitations

Examines organizer information and links contained in meeting invitations.

See Safemarker in your Microsoft 365 environment

Safemarker integrates with Microsoft 365 and can be deployed centrally by an administrator, without changes to your existing email flow.

Book a demo

Zo werkt het

E-mailbeveiliging gaat verder dan het bericht.

Ook een legitiem e-mailaccount kan gecompromitteerd zijn. Safemarker onderzoekt verzendgedrag, accountactiviteit en e-maildreigingen om verdachte activiteit te herkennen die gangbare authenticatiecontroles kunnen missen.

De bevindingen verschijnen direct in Outlook als een duidelijk beveiligingslabel, Vertrouwd, Let op, Hoog risico of Niet ondertekend, met onderbouwing en aanbevolen acties.

Afzendergedrag begrijpen

Safemarker vergelijkt beschikbare account- en verzendsignalen met vastgestelde patronen om activiteit te herkennen die op accountovername kan wijzen.

SignaalWat Safemarker controleertWaarom het telt
Apparaat

Eerder waargenomen en onbekende apparaten.

Een onverwacht apparaat kan wijzen op ongeautoriseerde toegang.

Browser & OS

Veranderingen in browser en besturingssysteem.

Onbekende omgevingen kunnen wijzen op ongebruikelijke activiteit.

Verzendende applicatie

Mailprogramma’s en applicaties waarmee berichten worden verstuurd.

Onverwachte applicaties kunnen wijzen op accountmisbruik.

Locatie & netwerk

Aanmeldlocaties, IP-adressen en netwerkwijzigingen.

Ongebruikelijke toegangspatronen kunnen wijzen op compromittering.

Aanmeldactiviteit

Riskante aanmeldingen en afwijkingen bij authenticatie.

Verdachte authenticatiegebeurtenissen geven extra context.

Verzendtijd

Tijdstip van het bericht vergeleken met historische activiteit.

Ongebruikelijke verzendtijden kunnen onderzoek rechtvaardigen.

Mailboxregels

Wijzigingen in doorstuur- en inboxregels.

Aanvallers kunnen regels gebruiken om berichten te verbergen of om te leiden.

Intentie van het bericht

Gevoelige verzoeken rond betalingen, inloggegevens of toegang.

Verzoeken met grote impact vragen om extra controle.

Soort mailbox

Gedeelde, individuele en geautomatiseerde mailboxen.

Verschillende soorten mailboxen vragen om verschillende gedragsbaselines.

Verificatie tussen organisaties

Afzenderverificatie tussen deelnemende Safemarker-organisaties.

Geeft extra zekerheid over het verzendende account.

Welke signalen beschikbaar zijn, hangt af van de afzender, de accounttoegang en de gekoppelde Microsoft 365-omgeving. Safemarker herkent verdachte patronen; het kan niet vaststellen wie een bericht fysiek heeft geschreven en garandeert niet dat elke compromittering wordt gedetecteerd.

Dreigingen die Safemarker detecteert

Safemarker combineert beschikbare accountactiviteit, afzendergedrag en e-mailanalyse om verdachte berichten te herkennen.

Accountcompromittering

Zakelijke e-mailfraude (BEC)

Verdachte activiteit vanuit legitieme e-mailaccounts, waaronder accountovername, compromittering van leveranciers en het kapen van conversaties.

Accountovername · Leverancierscompromittering · Gekaapte conversaties

Afzenderimpersonatie

Lookalike-domeinen en weergavenamen die bekende contacten of organisaties nabootsen.

Betalingsfraude

Verdachte verzoeken rond bankgegevens, betaalinstructies of betaalportalen.

Credential phishing

Verdachte inlogpagina’s via links of QR-codes.

Agenda-phishing

Kwaadaardige links en verdachte organisatoren in vergaderuitnodigingen.

Een baseline opbouwen

Safemarker bouwt gedragsbaselines op uit beschikbare historische activiteit, waaronder veelgebruikte apparaten, applicaties, locaties en verzendtijden.

Nieuwe of onbekende afzenders hebben beperkte geschiedenis. In die gevallen leunt Safemarker zwaarder op beschikbare e-mail-, domein- en authenticatiesignalen totdat er voldoende gedragsgegevens zijn.

Aanvullende e-mailcontroles

Naast accountactiviteit onderzoekt Safemarker indicatoren op berichtniveau om impersonatie, phishing en andere e-maildreigingen te herkennen.

Domeinreputatie & impersonatie

Controleert domeinreputatie, registratiegeschiedenis en gelijkenis met bekende domeinen.

Verificatie van weergavenaam

Herkent inconsistenties tussen afzendernamen, e-mailadressen en bekende contacten.

E-mailauthenticatie

Beoordeelt SPF-, DKIM- en DMARC-resultaten. Geslaagde authenticatie bewijst niet dat een account niet gecompromitteerd is.

Gedrag van externe afzenders

Onderzoekt afzendergeschiedenis, communicatiefrequentie en ongebruikelijke veranderingen in vaste patronen.

Linkanalyse

Controleert URL’s en hun bestemmingen op verdachte of kwaadaardige activiteit.

QR-codeanalyse

Haalt URL’s uit QR-codes en beoordeelt ze.

Agenda-uitnodigingen

Onderzoekt organisatorgegevens en links in vergaderuitnodigingen.

Zie Safemarker in je Microsoft 365-omgeving

Safemarker integreert met Microsoft 365 en kan centraal door een beheerder worden uitgerold, zonder wijzigingen in je bestaande mailstroom.

Plan een demo