Skip to main content
Email Security Intelligence

Who else has access
to your inbox?

Hidden forwarding rules. Unauthorized delegates. Stolen credentials. InboxWatch reveals what spam filters and antivirus can't see, built for IT teams and MSPs.

Gmail
Microsoft 365
Metadata only, never email content
Start Free Scan15 free scans · No credit card required
See what we detect
inboxwatch.ai/scan-results
At Risk
Issues found
53 critical
Checks run
100Complete
Forwarding Rules
OAuth Apps
Sign-in Activity
Spoofing Protection
Critical3 days undetected
Hidden Forwarding Rule

All incoming email is being silently copied to:

attacker-inbox@proton.me

You were not notified.

No malware. No phishing link. Just a settings change nobody saw.

Simple Setup

Secured in Minutes

No agents. No email access. Connect via OAuth and your first scan runs instantly.

Step 01

Connect

Connect in 10 seconds via official OAuth. We request only metadata, never your message content.

Step 02

Scan

100+ checks scan forwarding rules, OAuth apps, sign-in activity, and spoofing protection.

Step 03

Review

Every finding explained in plain English with severity, impact, and a security score.

Step 04

Fix

Step-by-step fix guides and continuous monitoring as often as every 30 minutes.

Verify our permissions yourself

We only request metadata access, never email content. Verify it yourself:

$55B

Lost to email compromise since 2013

Attackers set up hidden forwarding rules after they're already in, silently draining your inbox.

FBI IC3, September 2024

83%

Of account takeovers bypass MFA

Most tools only watch inbound messages.

Proofpoint 2024

70%

Of breaches involve the human element

Phishing gets them in. What happens to your inbox after goes completely undetected.

Verizon DBIR 2024

30s

To create a hidden forwarding rule

No malware needed. Just a settings change nobody sees.

InboxWatch Research

What Google & Microsoft miss.

Defender and Google catch inbound threats. InboxWatch finds attackers who are already in.

Feature comparison: InboxWatch vs Microsoft Defender vs Google security
Security capabilityInboxWatchDefenderGoogle
Score18/184/182/18
Business email compromise detectionPartialPartial
Hidden forwarding rule detection
Third-party OAuth app risk scoringPartialPartial
Dark web credential monitoring
Phishing simulation campaigns
Attack chain correlation
Impossible travel & sign-in anomaly detectionPartial
Delegate & shared mailbox audit
Calendar event scanning
Google Drive / OneDrive sharing auditPartial
Detection
Inbound email threat analysis
Protection
DMARC / brand impersonation monitoringPartialPartial
Lookalike domain detectionPartial
Operations
Monitoring frequencyEvery 30 minManual / DailyManual / Daily
MSP cross-tenant correlation
AI-powered false positive suppression
Privacy & Setup
Reads your email contentNeverYesYes
Setup time2 minutesDays/WeeksHours

* Metadata only. We never request body-reading scopes.

Your email stays yours

InboxWatch scans infrastructure, not inboxes. Here's exactly what we access and what we don't.

Official OAuth

Same secure sign-in as Google and Microsoft. We never store your password.

Metadata only

We scan headers, rules, and settings. Never message bodies or attachments.

No admin access needed

Connect your own account in 60 seconds. No IT department required.

Revoke anytime

Remove InboxWatch from your account settings. Access ends immediately.

Broader email risk coverage

Beyond the core scanner: phishing tests, breach monitoring, domain protection, and continuous risk assessment.

Email Exposure Map

Every service with your email, their auth grades, and breach history.

Learn more →

Phishing Simulations

Realistic campaigns with click and reporting rate tracking.

Learn more →

Breach Monitoring

Alerts when credentials surface on the dark web.

Learn more →

Domain Impersonation

Lookalike domain detection for your brand.

Learn more →

AI-Powered Analysis

Nightly review reduces false positives automatically.

Learn more →

Trusted Senders

Whitelist known senders so they stop triggering alerts.

Learn more →

Sign-in Anomalies

Impossible travel and suspicious login detection.

Learn more →

Attack Chain Correlation

Connects isolated findings into threat patterns.

Learn more →
AI-Powered

Less noise. More real threats.

InboxWatch learns your environment over time, automatically suppressing false alarms so your dashboard stays focused on what actually needs attention.

Learns your patterns

Mark a false positive once and the AI remembers. Trusted senders and known configs stop generating alerts automatically.

Suppresses noise

High false-positive findings are automatically suppressed. Your dashboard stays focused on real threats.

Full transparency

See what the AI suppressed, why, and restore anything with one click. Track accuracy trends and review history.

Built for AI agents

MCP server, REST API, and webhook alerts. Integrate into any workflow.

View docs →

Frequently Asked Questions

Yes. InboxWatch uses official OAuth, the same secure sign-in you use with other trusted apps. We request only metadata permissions (mail headers, rules, sign-in logs) and never access message content. You can revoke access instantly from your Google or Microsoft account settings.

See what's hiding in your inbox.

No credit card required · 15 free scans · Cancel anytime

$0.10/scan after free scans