The invoice you were half expecting
A bill arrives for work that sounds plausible. Paying it sends your money to someone else entirely.
Check suspicious emails. Spot requests to pay somewhere new. Watch the domains attackers use. A second opinion, alongside your existing security.
Check this emailInbox
Notes from Tuesday's planning meeting
Hi Alex,
Thanks for joining on Tuesday. I have put the notes in the shared folder under Planning, and the next meeting is on the 6th at ten.
Could you bring the figures for the second quarter? No rush before then.
Thanks, Sam
This verdict is for: Notes from Tuesday's planning meeting
Nothing that could be checked looked wrong. Treat any unexpected request with the usual care.
The available checks did not find significant phishing indicators. Mainly: authentication passes reported.
Technical detailsWe could not deliver your parcel
Dear customer,
We tried to deliver your parcel today but nobody was available to sign for it. A redelivery fee of £1.99 is due before we can try again.
Arrange redelivery and pay the fee: https://parcelwise-redelivery.example/pay
If the fee is not paid within 48 hours, your parcel will be returned to the sender.
Parcelwise Delivery
This verdict is for: We could not deliver your parcel
Take care with this one. Do not type any password or card details, and check with the sender another way before you act on it.
Get you to open, review or act on a delivery or document
The email contains indicators that deserve investigation. Mainly: a parcel held for a fee, from a sender the courier does not use.
Technical detailsUpdated bank details for invoice 4471
Hello Alex,
Our bank details have changed. Please pay invoice 4471 to our new account today to avoid a late payment fee, and update your records for future payments.
View the invoice and the new details: https://brindlewood-invoices.example/view/4471
Please confirm once the payment has been sent.
Kind regards, Accounts team
This verdict is for: Updated bank details for invoice 4471
Do not click any links, open attachments or reply to this email.
Get you to provide personal or financial information
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: payment change with a warning sign.
Technical detailsUnusual sign-in activity on your account
Microsoft account
Unusual sign-in activity
We detected something unusual about a recent sign-in to the Microsoft account alex@yourfirm.example. To keep your account safe, sign in and review your recent activity within 24 hours, or your account will be locked.
Review recent activity: https://micros0ft-account.example/verify
Thanks, The Microsoft account team
This verdict is for: Unusual sign-in activity on your account
Do not click any links, open attachments or reply to this email.
Get you to sign in or reveal account access
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: possible brand impersonation.
Technical detailsQuick favour
Alex,
Are you at your desk? I need you to buy four £100 gift cards for a client this morning. Keep this between us for now, I will explain later.
Reply with the codes as soon as you have them.
Chris
This verdict is for: Quick favour
Do not click any links, open attachments or reply to this email.
Get you to carry out a business request
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: asked to buy gift cards and send the codes.
Technical detailsIt sits after your filtering has had its turn, on the message that arrived because nothing about it was technically wrong. Keep whatever protects your inbox today.
Look after a business? Check free whether anybody can send email as your domain
Help your people handle threats, watch for exposure around your business, and show what you are doing about it. Jatzo is the platform. The tools under it are modules, and which ones you have depends on your plan.
Give your team a second opinion on suspicious messages, with clear evidence and a practical next step.
Email Threat Analyser on the website, every plan. In Outlook and Gmail from Personal, with shared cases for a team.
How the analyser worksWatch your domains for spoofing weaknesses and lookalikes. Understand the threats reaching your people.
The organisation threat report with Business. Domain Watch with Business Pro.
What monitoring coversHelp staff recognise the warning signs and practise the decisions that matter.
Jatzo Training, its assessments and certificates, with Business Pro.
Explore the trainingKeep a record of your checks, training and activity, with reports and a dated proof pack.
PDF reports from Personal. Activity records, exports and the dated Proof Pack with Business Pro.
What each plan includesThe Invoice Fraud Checker belongs to the same family and is sold on its own: a separate Windows licence, never part of a subscription here. About invoice checks
Some of that money left because somebody believed an email. We look at the email.
Figures for 2025 from the UK Finance Annual Fraud Report 2026.
The scale of the problem, in figuresFits the way your team works.
A strange invoice. An unexpected login link. Check it with Jatzo in Outlook or Gmail, where you are reading it, or on the website.
Where Jatzo worksA score out of 100, then what raised a concern and why it matters, in plain English, with the technical detail there when you want it.
Try it on a real lureEvery result ends with what to do next, so nobody has to become a security expert to handle a suspicious email well.
Built for your whole team169detection rules
Before a rule can score anything, it says which question it answers. That is how a marketing email and an attack on your money are kept apart.
Evidence that a message wants credentials, money or access. Only this can raise a message to High risk.
Spam and marketing, scored on a channel of its own. Never enough, alone, to call something phishing.
What could not be checked. Said plainly, and scores nothing in either direction.
A message designed to fool you is built to look ordinary. Here are four that reach ordinary inboxes, and every one of them arrives looking like routine admin.
A bill arrives for work that sounds plausible. Paying it sends your money to someone else entirely.
Someone has accessed your account, sign in to secure it. The sign-in page is theirs, and now so is your password.
A delivery is held pending a tiny charge. The amount is trivial, which is the point. What they want is the card number.
A familiar contact sends new account details before an invoice is due, and the next payment goes to somebody else.
INVOICE FRAUD CHECKER
A Windows program that keeps the bank details you have confirmed for each supplier. When an invoice asks you to pay somewhere new, it says stop, and says why. It runs on your own computer, and your suppliers' bank details are never sent to Jatzo.
A separate yearly licence, not part of a Jatzo subscription.
| On this invoice | Confirmed | |
|---|---|---|
| Sort code | 20-00-00 New | 12-34-56 |
| Account | ending 7701 New | ending 5432 |
Stop: do not pay this yet. Call Acme Supplies on a number you already have and confirm the new bank details first.
The other half of email fraud is the mail sent in your name. If your domain does not tell receiving systems to refuse a fake, anybody can send an invoice from your address to your customers, and it will look exactly like you.
History keeps the subject, score and compact findings. It does not keep the raw email or attachment contents.
Jatzo reads the message and its attachments to run the analysis, then releases them. The raw email, its contents and its attachments are not saved in your history. What is kept is the subject line, the score, the short list of findings and a few counts, such as how many links there were, so you can recognise a check later. In your history, links and senders are kept only as keyed fingerprints that cannot be read back, which is how Jatzo notices the same campaign returning. The detailed evidence behind a PDF report, such as the full links, is held in memory for up to 30 minutes and then deleted.
Jatzo reads the submitted message and supported attachments to produce the analysis, then releases them from application processing.
History saves the subject, score and compact findings. It does not save the raw email or attachment contents. Subjects may contain personal information.
Supported uploads are processed in restricted workers. This reduces risk; it does not make an attachment safe to open on your own device.
The current email engine uses programmed checks and scoring. It does not send your email to a generative-AI model for analysis.
Tap anything in this email that looks suspicious. Then see what Jatzo found, including what nobody can see in an inbox.
Microsoft 365 <account-security@micros0ft-account.example>
To: Alex Morgan
Unusual sign-in activity on your account
Microsoft account
Unusual sign-in activity
We detected something unusual about a recent sign-in to the Microsoft account alex@yourfirm.example. To keep your account safe, sign in and review your recent activity within 24 hours, or your account will be locked.
Review recent activity: https://micros0ft-account.example/verify
Thanks, The Microsoft account team
0 of 6 found
Tap or press the parts that worry you.
In the email you could see
A known brand's name from a domain it does not use, with signs of disguise, is impersonation.
Alarm about your account is used to rush you into signing in on a copied page.
Talk of passwords or sign-in beside a request is how credential theft starts.
Time pressure is used to stop people checking before they act.
Threats of closure or legal action are used to rush a decision.
Something about the link is unusual enough to check before clicking.
Out of sight, in the sender and the headers
A fake warning about your account from a brand that did not send it is how account takeover starts.
Without a signature nothing shows the message is unaltered or really from this domain.
Without it, nothing stops someone else using this From domain.
What to doDo not use the supplied sign-in path. Open the real service independently and check your account there.
A fictional email. Every reason, its points and the advice are what Jatzo returns for it. Open the full demo
FOR BUSINESSES
Law, accountancy, property and anybody whose finance team pays suppliers on emailed instructions. Staff get a practical way to question a message before they act on it, and whoever looks after your IT gets the findings behind it.
Explore Jatzo for business ↗︎Check. Understand. Act.
FOR MANAGED SERVICE PROVIDERS
Add a service your clients can understand and your engineers can work with. Manage separate client organisations, each with its own records and its own activity log.
Explore the MSP partnership ↗︎Short, practical lessons built around real situations, with feedback that explains every answer.
The first lesson is free. Every course is included with Business Pro.
A team plan is billed per person, and the rate steps down as you add more. Prices are the total you pay, with no VAT added.
Give a whole team the same answer, in the inbox they already use.
£8per person a month, from 2 people
Everyone signs in as themselves, one allowance shared across the team, and one place to manage it.
See the planSee what is reaching your people, and manage how it is handled.
£12per person a month, from 5 people
The whole training catalogue for everybody you add, a daily watch on your own domains, and a dated pack that shows what you do.
See the planDeployed and integrated around how your organisation already works.
Agreed with youfrom 50 people
Ask about your teamJust for you? Five checks a month are free, and Personal is £6 a month for Jatzo inside your own Outlook or Gmail. Compare every plan
Paying suppliers by bank transfer? The Invoice Fraud Checker is a separate licence, from £129 a year. What it checks