INTERACTIVE DEMO
Open a suspicious email. See what Jatzo says.
Five fictional emails in an example inbox, and the answer Jatzo gives for each one. Open the inbox, pick a message, and read the pane beside it. Nothing is sent, nothing is checked live and no account is needed.
Inbox
Notes from Tuesday's planning meeting
Hi Alex,
Thanks for joining on Tuesday. I have put the notes in the shared folder under Planning, and the next meeting is on the 6th at ten.
Could you bring the figures for the second quarter? No rush before then.
Thanks, Sam
This verdict is for: Notes from Tuesday's planning meeting
Nothing that could be checked looked wrong. Treat any unexpected request with the usual care.
The available checks did not find significant phishing indicators. Mainly: authentication passes reported.
Technical detailsWe could not deliver your parcel
Dear customer,
We tried to deliver your parcel today but nobody was available to sign for it. A redelivery fee of £1.99 is due before we can try again.
Arrange redelivery and pay the fee: https://parcelwise-redelivery.example/pay
If the fee is not paid within 48 hours, your parcel will be returned to the sender.
Parcelwise Delivery
This verdict is for: We could not deliver your parcel
Take care with this one. Do not type any password or card details, and check with the sender another way before you act on it.
Get you to open, review or act on a delivery or document
The email contains indicators that deserve investigation. Mainly: a parcel held for a fee, from a sender the courier does not use.
Technical detailsUpdated bank details for invoice 4471
Hello Alex,
Our bank details have changed. Please pay invoice 4471 to our new account today to avoid a late payment fee, and update your records for future payments.
View the invoice and the new details: https://brindlewood-invoices.example/view/4471
Please confirm once the payment has been sent.
Kind regards, Accounts team
This verdict is for: Updated bank details for invoice 4471
Do not click any links, open attachments or reply to this email.
Get you to provide personal or financial information
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: this failed the sender's own anti-forgery check.
Technical detailsUnusual sign-in activity on your account
Microsoft account
Unusual sign-in activity
We detected something unusual about a recent sign-in to the Microsoft account alex@yourfirm.example. To keep your account safe, sign in and review your recent activity within 24 hours, or your account will be locked.
Review recent activity: https://micros0ft-account.example/verify
Thanks, The Microsoft account team
This verdict is for: Unusual sign-in activity on your account
Do not click any links, open attachments or reply to this email.
Get you to sign in or reveal account access
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: possible brand impersonation.
Technical detailsQuick favour
Alex,
Are you at your desk? I need you to buy four £100 gift cards for a client this morning. Keep this between us for now, I will explain later.
Reply with the codes as soon as you have them.
Chris
This verdict is for: Quick favour
Do not click any links, open attachments or reply to this email.
Get you to carry out a business request
Multiple strong indicators suggest this email may be phishing or malicious. Mainly: asked to buy gift cards and send the codes.
Technical detailsIllustrative view of Jatzo in Outlook. The emails and the people in them are invented, and every address is under .example. The score, the wording and the reasons are what Jatzo really returns for each message.
WHAT TO TRY
Three things worth doing while you are here.
- Compare the two invoices. The supplier invoice and the ordinary meeting notes arrive looking equally routine. Open each and see which parts of the score they differ on.
- Read the reason, not just the number. Every score has a short reason above it and the full evidence behind Technical details. The number is the summary, not the argument.
- Look at what could not be checked. Jatzo says what it could not establish as plainly as what it found. A low score is not a promise that a message is safe.
THE SAME ANSWER, ON THE WEBSITE
Every score tells a story.
The pane in the inbox and the result on the website are two views of one answer. Here are three of the same messages, worded the way the website words them.
FICTIONAL EMAIL
Updated bank details for invoice 4471
- From
- Brindlewood Supplies <accounts@brindlewood-billing.example>
- Reply-To
- payments@brindlewood-accounts.example
- Your provider checked
- SPF: fail for brindlewood-billing.example (the envelope sender)DKIM: noneDMARC: fail for brindlewood-billing.example (the From domain)
Hello Alex,
Our bank details have changed. Please pay invoice 4471 to our new account today to avoid a late payment fee, and update your records for future payments.
View the invoice and the new details: https://brindlewood-invoices.example/view/4471
Please confirm once the payment has been sent.
Kind regards, Accounts team
Multiple strong indicators suggest this email may be phishing or malicious. Do not click links, open unexpected attachments, or provide sensitive information until independently verified.
What it wantsGet you to provide personal or financial information
Top reasons for this score
Select a reason to see where it is in the email.
ObservedSupplied headers report DMARC failure.
Why it mattersThe domain in the From line did not authorise this message.
ObservedThe message appears to change supplier, beneficiary or remittance details.
Why it mattersA change to supplier bank details is the main step in invoice fraud.
ObservedAvailable headers report an SPF failure or soft failure.
Why it mattersThe server that sent this is not one the domain allows to send its mail.
ObservedFrom uses brindlewood-billing.example, while Reply-To uses brindlewood-accounts.example.
Why it mattersYour reply would go to a different domain from the one you see.
ObservedA result in this message reports DKIM=none, but Jatzo could not verify it.
Why it mattersWithout a signature nothing shows the message is unaltered or really from this domain.
ObservedThe message combines invoice, statement or remittance language with payment pressure and an attachment or destination.
Why it mattersPressure to pay an invoice quickly is how payment fraud gets past normal checks.
Recommended action
Do not submit sensitive information through the email's links until the organisation and destination are independently verified.
FICTIONAL EMAIL
Unusual sign-in activity on your account
- From
- Microsoft 365 <account-security@micros0ft-account.example>
- Your provider checked
- SPF: pass for micros0ft-account.example (the envelope sender)DKIM: noneDMARC: none for micros0ft-account.example (the From domain)
Microsoft account
Unusual sign-in activity
We detected something unusual about a recent sign-in to the Microsoft account alex@yourfirm.example. To keep your account safe, sign in and review your recent activity within 24 hours, or your account will be locked.
Review recent activity: https://micros0ft-account.example/verify
Thanks, The Microsoft account team
Multiple strong indicators suggest this email may be phishing or malicious. Do not click links, open unexpected attachments, or provide sensitive information until independently verified.
What it wantsGet you to sign in or reveal account access
Top reasons for this score
Select a reason to see where it is in the email.
ObservedThe display identity invokes Microsoft, but the From address uses micros0ft-account.example.
Why it mattersA known brand's name from a domain it does not use, with signs of disguise, is impersonation.
ObservedThe message poses as a well known organisation from a domain that organisation does not use, and warns about your account: a withdrawal, a change to your details or a sign-in from somewhere new.
Why it mattersA fake warning about your account from a brand that did not send it is how account takeover starts.
ObservedThe message uses an unusual-login, password, mailbox or MFA warning to prompt an account action.
Why it mattersAlarm about your account is used to rush you into signing in on a copied page.
ObservedThe email threatens account closure, legal action or another consequence.
Why it mattersThreats of closure or legal action are used to rush a decision.
ObservedA result in this message reports DKIM=none, but Jatzo could not verify it.
Why it mattersWithout a signature nothing shows the message is unaltered or really from this domain.
ObservedA result in this message reports DMARC=none, but Jatzo could not verify it.
Why it mattersWithout it, nothing stops someone else using this From domain.
ObservedThe message uses urgency or pressure to encourage immediate action.
Why it mattersTime pressure is used to stop people checking before they act.
ObservedThe message mentions authentication information in the context of an action or request.
Why it mattersTalk of passwords or sign-in beside a request is how credential theft starts.
Observedmicros0ft-account.example/verify: URL contains a sensitive action keyword; Destination shares the sender's registered domain (micros0ft-account.example); Domain resembles Microsoft (microsoft.com) but is a different registered domain
Why it mattersSomething about the link is unusual enough to check before clicking.
Recommended action
Do not use the supplied sign-in path. Open the real service independently and check your account there.
FICTIONAL EMAIL
Notes from Tuesday's planning meeting
- From
- Sam Patel <sam.patel@yourfirm.example>
- Your provider checked
- SPF: pass for yourfirm.example (the envelope sender)DKIM: pass for yourfirm.example (the signing domain)DMARC: pass for yourfirm.example (the From domain)
Hi Alex,
Thanks for joining on Tuesday. I have put the notes in the shared folder under Planning, and the next meeting is on the 6th at ten.
Could you bring the figures for the second quarter? No rush before then.
Thanks, Sam
The available checks did not find significant phishing indicators. This does not guarantee the email is safe.
What was checked
Select a line to see where it is in the email.
Recommended action
Treat unexpected links, attachments and requests cautiously and verify the sender independently before acting.
A low score is not a guarantee that an email is safe. Automated analysis can be wrong, and missing evidence is not proof of safety, so verify important requests through a route you trust.
Now try it on an email of your own.
Paste a message you are unsure about and get the same answer for it. One check needs no account at all.
