JatzoCyber Security

INTERACTIVE DEMO

Open a suspicious email. See what Jatzo says.

Five fictional emails in an example inbox, and the answer Jatzo gives for each one. Open the inbox, pick a message, and read the pane beside it. Nothing is sent, nothing is checked live and no account is needed.

OutlookSearch your inboxAM
HomeViewHelpReplyForwardCheck this email
New mailDrafts 2Sent itemsArchiveDeleted itemsFAVOURITESTeam updatesProjects

Updated bank details for invoice 4471

BSBrindlewood Suppliesaccounts@brindlewood-billing.exampleTo: Alex Morgan09:41

Hello Alex,

Our bank details have changed. Please pay invoice 4471 to our new account today to avoid a late payment fee, and update your records for future payments.

View the invoice and the new details: https://brindlewood-invoices.example/view/4471

Please confirm once the payment has been sent.

Kind regards, Accounts team

JatzoIs this email safe?

This verdict is for: Updated bank details for invoice 4471

Do not click any links, open attachments or reply to this email.

Email risk score
75/100 Risk gradeVery high risk

Get you to provide personal or financial information

Multiple strong indicators suggest this email may be phishing or malicious. Mainly: this failed the sender's own anti-forgery check.

Technical details

Illustrative view of Jatzo in Outlook. The emails and the people in them are invented, and every address is under .example. The score, the wording and the reasons are what Jatzo really returns for each message.

WHAT TO TRY

Three things worth doing while you are here.

  1. Compare the two invoices. The supplier invoice and the ordinary meeting notes arrive looking equally routine. Open each and see which parts of the score they differ on.
  2. Read the reason, not just the number. Every score has a short reason above it and the full evidence behind Technical details. The number is the summary, not the argument.
  3. Look at what could not be checked. Jatzo says what it could not establish as plainly as what it found. A low score is not a promise that a message is safe.

THE SAME ANSWER, ON THE WEBSITE

Every score tells a story.

The pane in the inbox and the result on the website are two views of one answer. Here are three of the same messages, worded the way the website words them.

FICTIONAL EMAIL

Updated bank details for invoice 4471

From
Brindlewood Supplies <accounts@brindlewood-billing.example>
Reply-To
payments@brindlewood-accounts.example
Your provider checked
SPF: fail for brindlewood-billing.example (the envelope sender)DKIM: noneDMARC: fail for brindlewood-billing.example (the From domain)

Hello Alex,

Our bank details have changed. Please pay invoice 4471 to our new account today to avoid a late payment fee, and update your records for future payments.

View the invoice and the new details: https://brindlewood-invoices.example/view/4471

Please confirm once the payment has been sent.

Kind regards, Accounts team

Email risk score
75/100 Risk gradeVery high risk

Multiple strong indicators suggest this email may be phishing or malicious. Do not click links, open unexpected attachments, or provide sensitive information until independently verified.

What it wantsGet you to provide personal or financial information

Top reasons for this score

Select a reason to see where it is in the email.

  • ObservedSupplied headers report DMARC failure.

    Why it mattersThe domain in the From line did not authorise this message.

  • ObservedThe message appears to change supplier, beneficiary or remittance details.

    Why it mattersA change to supplier bank details is the main step in invoice fraud.

  • ObservedAvailable headers report an SPF failure or soft failure.

    Why it mattersThe server that sent this is not one the domain allows to send its mail.

  • ObservedFrom uses brindlewood-billing.example, while Reply-To uses brindlewood-accounts.example.

    Why it mattersYour reply would go to a different domain from the one you see.

  • ObservedA result in this message reports DKIM=none, but Jatzo could not verify it.

    Why it mattersWithout a signature nothing shows the message is unaltered or really from this domain.

  • ObservedThe message combines invoice, statement or remittance language with payment pressure and an attachment or destination.

    Why it mattersPressure to pay an invoice quickly is how payment fraud gets past normal checks.

Recommended action

Do not submit sensitive information through the email's links until the organisation and destination are independently verified.

FICTIONAL EMAIL

Unusual sign-in activity on your account

From
Microsoft 365 <account-security@micros0ft-account.example>
Your provider checked
SPF: pass for micros0ft-account.example (the envelope sender)DKIM: noneDMARC: none for micros0ft-account.example (the From domain)

Microsoft account

Unusual sign-in activity

We detected something unusual about a recent sign-in to the Microsoft account alex@yourfirm.example. To keep your account safe, sign in and review your recent activity within 24 hours, or your account will be locked.

Review recent activity: https://micros0ft-account.example/verify

Thanks, The Microsoft account team

Email risk score
91/100 Risk gradeVery high risk

Multiple strong indicators suggest this email may be phishing or malicious. Do not click links, open unexpected attachments, or provide sensitive information until independently verified.

What it wantsGet you to sign in or reveal account access

Top reasons for this score

Select a reason to see where it is in the email.

  • ObservedThe display identity invokes Microsoft, but the From address uses micros0ft-account.example.

    Why it mattersA known brand's name from a domain it does not use, with signs of disguise, is impersonation.

  • ObservedThe message poses as a well known organisation from a domain that organisation does not use, and warns about your account: a withdrawal, a change to your details or a sign-in from somewhere new.

    Why it mattersA fake warning about your account from a brand that did not send it is how account takeover starts.

  • ObservedThe message uses an unusual-login, password, mailbox or MFA warning to prompt an account action.

    Why it mattersAlarm about your account is used to rush you into signing in on a copied page.

  • ObservedThe email threatens account closure, legal action or another consequence.

    Why it mattersThreats of closure or legal action are used to rush a decision.

  • ObservedA result in this message reports DKIM=none, but Jatzo could not verify it.

    Why it mattersWithout a signature nothing shows the message is unaltered or really from this domain.

  • ObservedA result in this message reports DMARC=none, but Jatzo could not verify it.

    Why it mattersWithout it, nothing stops someone else using this From domain.

  • ObservedThe message uses urgency or pressure to encourage immediate action.

    Why it mattersTime pressure is used to stop people checking before they act.

  • ObservedThe message mentions authentication information in the context of an action or request.

    Why it mattersTalk of passwords or sign-in beside a request is how credential theft starts.

  • Observedmicros0ft-account.example/verify: URL contains a sensitive action keyword; Destination shares the sender's registered domain (micros0ft-account.example); Domain resembles Microsoft (microsoft.com) but is a different registered domain

    Why it mattersSomething about the link is unusual enough to check before clicking.

Recommended action

Do not use the supplied sign-in path. Open the real service independently and check your account there.

FICTIONAL EMAIL

Notes from Tuesday's planning meeting

From
Sam Patel <sam.patel@yourfirm.example>
Your provider checked
SPF: pass for yourfirm.example (the envelope sender)DKIM: pass for yourfirm.example (the signing domain)DMARC: pass for yourfirm.example (the From domain)

Hi Alex,

Thanks for joining on Tuesday. I have put the notes in the shared folder under Planning, and the next meeting is on the 6th at ten.

Could you bring the figures for the second quarter? No rush before then.

Thanks, Sam

Email risk score
1/100 Risk gradeLow risk

The available checks did not find significant phishing indicators. This does not guarantee the email is safe.

What was checked

Select a line to see where it is in the email.

Recommended action

Treat unexpected links, attachments and requests cautiously and verify the sender independently before acting.

A low score is not a guarantee that an email is safe. Automated analysis can be wrong, and missing evidence is not proof of safety, so verify important requests through a route you trust.

Now try it on an email of your own.

Paste a message you are unsure about and get the same answer for it. One check needs no account at all.