Skip to main content
10 Threat Categories

Attackers don't hack your inbox.They exploit everything around it.

InboxWatch detects threats across your entire email attack surface without reading a single message.

Free for your first 15 scans. No credit card needed.

100+
Security checks
21
Critical detections
0
Emails read

What we can and can't see

We scan
  • Mail headers (from, to, date)
  • Forwarding rules & filters
  • OAuth app permissions
  • Sign-in logs & MFA status
  • Mailbox settings (POP, IMAP)
  • DNS records (SPF, DKIM, DMARC)
We never access
  • ×Email body content
  • ×Attachments or files
  • ×Contact lists
  • ×Calendar details
  • ×Drive files
  • ×Chat messages

Verify in your Google or Microsoft account settings.

What does InboxWatch scan for?

100+ security checks across 10 categories

Spoofing

Display name spoofing, typosquatting, homoglyph domains

CEO name paired with an external freemail address

Phishing

Credential harvesting links, fake login pages

Deceptive URLs mimicking Microsoft or Google sign-in

Auth Validation

SPF, DKIM, and DMARC pass-rate grading per sender domain

Domains failing authentication on inbound email

Account Security

Impossible travel, risky OAuth grants, MFA status

Sign-in from two countries within the same hour

Domain Protection

Lookalike detection, brand impersonation, exposure mapping

Newly registered domain one character off from yours

Attachments

Executable extensions, macro-enabled files, double extensions

Invoice.pdf.exe masquerading as a document

Temporal

After-hours sends, volume bursts, weekend anomalies

50 outbound messages sent at 3 AM from your account

Link Analysis

Shortened URLs, redirect chains, suspicious destinations

Bit.ly link resolving to an unknown login page

Inbound Threats

Business email compromise, forwarding rules, filter manipulation

Hidden rule forwarding all mail to an external address

Calendar/Drive

Risky calendar invites, public sharing, external access

Sensitive Drive folder shared publicly without expiry

11-stage scan pipeline

Every scan passes through a multi-stage pipeline, from connection to notification in under 60 seconds.

1
Connect
2
Detect
3
Dedup
4
Whitelist
5
Feedback
6
AI Dismiss
7
Identify New
8
Attack Chain
9
Score
10
Save
11
Notify
Coverage by Account Type

100 detections. Every account type.

Coverage varies by provider API availability and our metadata-only OAuth scopes. Numbers show alertable detections per account type.

Category
Personal Gmail
@gmail.com
Workspace Gmail
@company.com
Personal Outlook
@outlook.com
Work Microsoft
Microsoft 365
Rules993
Access316
Spoofing6655
Settings6614
Security10101016
Inbound131389
Total Alertable44472543

Why Personal Outlook shows 25 vs 43

  • Mailbox rules API returns 403 for consumer accounts
  • Sign-in activity, MFA status, and recovery options require org-level APIs
  • No delegate access or password age APIs for personal accounts

Privacy-First Scope Constraints

  • Gmail: gmail.metadata only (never gmail.readonly)
  • Microsoft: Mail.ReadBasic only (never Mail.Read)
  • Zero email body access across all account types
  • All 100 detections work without reading message content

Run all 76 checks on your account. Free.

See which of the 21 critical detections apply to you. Results in under 60 seconds.

15 free scans · No credit card required