EMAIL SECURITY FOR MARKETING AND DIGITAL AGENCIESClient logins,
kept out of the wrong hands.

An agency holds the logins to its clients' websites, ad accounts and social media, and sends each of them an invoice every month. One convincing email to the wrong person can reach all of it.

A fictional email08:36
FromFacebook Ads Supportno-reply@adspolicy-review.example
ToAlex Morgan
SubjectAction required: your Facebook ad account has been restricted
ChecksSPF pass, DKIM pass, DMARC none

Hi Alex,

Your Facebook ad account has been restricted because recent activity does not follow Meta's advertising standards. Ads managed by your business in Meta Business Suite will stop delivering until the account is reviewed.

If you believe this is a mistake, you can request a review. To protect the accounts you manage, sign in with your business loginnote 1 to confirm that you manage this account.

Note 1: Asks for the login to client accounts

Request a review: https://business-adsupport-appeals.example/reviewnote 2

Note 2: Not the platform's own web address

If we do not receive a request within 24 hours, the restriction will become permanentnote 3 and the ad accounts you manage may be disabled.

Note 3: A deadline to stop you checking

Meta for Business Support

61out of 100

High riskJatzo's result for this fictional email

What moved the score

  • Possible brand impersonation+22
  • Claimed organisation differs from sender domain+10
  • Threat or consequence language+9

and 3 more

The numbered notes point out what to look for. The score and the reasons beside it are Jatzo's own result for this email, which was written for this page. Every name and address in it is invented.

Invoice and mandate fraud, as UK Finance recorded it.

  • £41.3 millionlost to invoice and mandate fraud in 2025
  • 2,305cases recorded in the year
  • 68%of the losses came from business accounts

Criminals intercept emails or take over an email account, then pose as a supplier, a solicitor or a builder with new bank details. UK Finance, Annual Fraud Report 2026, June 2026 (opens in a new tab)

What marketing and digital agencies worry about.

And what Jatzo does about each, in the inbox your team already uses.

  1. A client's ad account taken over

    Emails posing as Meta or Google ask an agency to sign in about a restricted account, and the login they take is your client's.

    What Jatzo does

    The check names an email that borrows a brand it does not come from, and requests for a password or a sign-in code, before anybody signs in.

    Every plan
  2. Your invoices to clients diverted

    An agency is a supplier to every client. A fraudster who can send as you, or from a lookalike of your domain, can tell them all to pay somewhere new.

    What Jatzo does

    Domain Watch checks whether anybody could send email as your domain, and watches for new web addresses made to look like it.

    Business Pro
  3. Hacked accounts asking for money

    Report Fraud's first annual assessment put losses from hacked email and social media accounts at £6.3 million in 2025-26, up from £1.2 million the year before.

    What Jatzo does

    Training shows everyone who holds a client login what these emails look like, with a record of who completed each course.

    Business Pro

How it unfolds for marketing and digital agencies.

  1. Check it here

    A platform notice arrives

    An email posing as an ad or social platform's policy notice or partner invitation asks the agency to act.

  2. A sign-in page

    Its link leads to a page that collects the business login and the two-step code.

  3. Client accounts are taken

    With that login, the criminal controls the client accounts it reaches.

  4. Money is asked for

    The hacked accounts are then used to ask people for money, in the client's name.

The gold mark is where Jatzo's check fits: somebody has the email open and nothing has been paid yet.

The check before you pay.

Six steps, every time. Print it, put it by whoever pays the invoices, and agree that nobody skips it because somebody senior is in a hurry.

Download the one-page checklist (PDF)
  1. Keep every client login in a password manager, never in email, chat or a shared document.

  2. Turn on two-step verification on every client account you hold, with an app or security key rather than a text message where the service allows it.

  3. Treat any email asking you to sign in, accept a partner request or restore access as suspect, and go to the service yourself rather than through the link.

  4. Tell every client in writing that your bank details will never change by email.

  5. If a client's bank details change by email, ring them on a number you already hold before paying.

  6. If money has gone, ring your bank's fraud line at once, then report to Report Fraud on 0300 123 2040 or reportfraud.police.uk (Police Scotland on 101 in Scotland).

    Also on day one: tell each client whose account may be affected, change their passwords from a device you trust, and use each platform's own recovery process.

What the agency gets.

It does not replace the call. It makes sure somebody makes it. Jatzo adds a check beside the message in Outlook and Gmail, at the moment somebody decides whether to pay, reply or click, and your existing email protection stays as it is.

  • Check the notice before signing in

    Every plan

    Anybody unsure about a platform notice or partner request presses Check in Outlook or Gmail and sees a score out of 100 with the reasons.

  • Training for everyone holding client logins

    Business Pro

    Business Pro includes every Training Centre course, Protecting your work account among them, for everyone in the team, with a record of who completed it.

  • Your managing director hears at once

    Business and Business Pro

    When anybody checks a message scoring High risk or above, an email goes to addresses you choose at your own domain, such as your managing director's.

  • Addresses made to look like yours

    Business Pro

    Domain Watch, on Business Pro, looks for new web addresses registered to look like your agency's, the address a fake invoice to your clients would come from.

  • See what is aimed at the agency

    Business and Business Pro

    The organisation threat report counts the checks that reached Suspicious or above by kind of attack, the last 30 days against the 30 before, and names nobody.

  • For the invoices the agency pays

    Separate licence, from £129 a year

    Invoice Fraud Checker, a separate Windows program, compares the bank details on each invoice with the ones you confirmed for that supplier.

Which plan fits: an example

For marketing and digital agencies with 10 people, we suggest Business Pro: £120 a month, or £1,200 a year paid annually.

That is £12 a person a month.

Training for everyone who holds a client login, and Domain Watch for addresses that copy yours, are both on Business Pro.

Business Pro includes the threat report, so you know what is being aimed at the agency and whether it is getting worse: every email your team checked that came back Suspicious or above, by kind of attack, the last 30 days against the 30 before, naming nobody. At the start of each month a report goes by email to the addresses you choose, saying what was checked and what is still waiting.

  • The Check button in Outlook, including on a phone, and in Gmail, for everybody in the team.
  • Staff do nothing. Whoever looks after your email adds it once, for everybody.
  • Nothing to replace. Your email, and the protection it already has, stay as they are.
  • Jatzo keeps the score and the findings for up to 90 days, never the email or its attachments.
  • Pay monthly, or a year in advance for ten months' price.

The Invoice Fraud Checker is a separate licence, from £129 a year. About the Invoice Fraud Checker

What your sector's own bodies say.

Each point is linked to where it was published, with its date.

Use multi-factor authentication on every online service the organisation relies on, and prefer the kinds that resist phishing.

NCSC, Multi-factor authentication for your corporate online services, September 2024 (opens in a new tab)

Fraudsters hack supplier email accounts or create lookalike domains to send fake invoices with updated bank details; confirm the old and new details on a known phone number, not one in the message.

GOV.UK, Stop! Think Fraud: Protect your business, current guidance (opens in a new tab)

Report Fraud replaced Action Fraud in December 2025. The number, 0300 123 2040, did not change. GOV.UK, Report Fraud: new service from City of London Police, December 2025 (opens in a new tab)

Questions marketing and digital agencies ask.

Does Jatzo check the link in a platform notice?

Yes. Jatzo looks at where each link leads, at lookalike addresses and at senders that do not match who they claim to be, and checks links against Google Web Risk. A brand new sign-in page may not be listed anywhere yet, so the result weighs the sender and the wording as well.

Does it replace two-step verification?

No. The NCSC advises two-step verification on every service you rely on, preferably a kind that resists phishing. Jatzo helps somebody notice a fake sign-in request before they type a code into it.

Does Jatzo read our client accounts or the rest of the mailbox?

No. Jatzo reads only the email somebody chooses to check, and the add-in cannot reply, forward, move, delete or change anything in the mailbox. It keeps the subject line, the score and the findings for up to 90 days, never the message or its attachments. Links in it are checked against Google Web Risk.

Will our IT company need to do anything?

A little, once. Whoever looks after your email proves your domain with one DNS record. For Microsoft 365 they then upload one file in the admin centre, which needs the Exchange Administrator or Global Administrator role, and Microsoft takes 24 to 72 hours to add the button. For Google Workspace they install Jatzo for the domain. Staff do nothing.