Upload a DMARC report (the .zip or .xml your mailbox sends you) or a suspicious email (a .eml file) and we will explain it in plain English: who really sent it (the actual services, named), whether it authenticated, how your domain's own security setup grades, the links and attachments, and whether our network already flags any of the senders. Free, no account needed.
Want continuous protection, not a one-off check? Forward suspicious emails to Sender Registry for a full assessment backed by the network, or start free.
For developers
Check disposable emails, Tor IPs, risky domains, spoofability and known-bad senders in one API call. Free to start.
You can change this at any time.
Every object in the registry (a sender, a domain, a campaign) moves through five stages as independent evidence builds:
This is deliberately separate from Risk and Confidence. How much of the network agrees is a different question from how dangerous something looks, or how certain we are.
Every campaign gets scored across 8 axes: infrastructure, domain patterns, message templates, link behaviour, attachment patterns, target industries, target roles, and campaign velocity. All plotted as a fingerprint.
Sender Registry compares every campaign's fingerprint against every other campaign's using cosine similarity: the same technique used to compare documents by meaning, not just matching words. A high match (we only ever suggest one above 55% similarity) means two campaigns that look unrelated on the surface may share real infrastructure, even under completely different domain names.
Senders, domains, URLs, attachments, campaigns, brands and suppliers all become nodes in a shared relationship graph, built from real evidence: a sender using a domain, a domain appearing in the same report as another domain, a report belonging to a campaign.
On a phone, we deliberately don't force a giant graph onto a small screen. Instead you get a focused view: the object you're looking at, and everything directly connected to it, with a tap to move to any of those connections in turn.
Add Sender Registry to your home screen and turn on notifications from your account - both free, both take under a minute. From then on, anything urgent (a payment-diversion campaign, an executive impersonation attempt) reaches you as a real notification on your lock screen, the same way any other app alerts you.
Every notification is sent end-to-end encrypted directly to your device - nothing is readable in transit by anyone other than your phone.
Open Verify Before You Act, point your camera at a QR code, and capture it. The image is decoded and the destination it leads to is checked exactly the same way we already check a QR code found inside a forwarded email - the same detection, just with your camera as the front door.
You'll see whether the destination is safe, blocked, or worth a second look, with a plain explanation either way.
On Android, once the app is added to your home screen, "Sender Registry" simply appears as an option in your phone's normal Share menu - the same one you'd use to send a photo to a friend. Share a suspicious text or link straight in, review it, and submit.
On iPhone, Apple's own software doesn't allow a website to appear in the Share menu automatically. A short, one-time setup (a free "Shortcut") gets you the same result - after that one step, it behaves identically on both phones.