Brand Protection
What it does
Brand Protection detects impersonation attacks that generic filters miss. Working from a brand list you curate, it covers the full range of impersonation tactics — from look-alike domains to display-name and subject-line spoofing — including CJK/Japanese native-script variants that Western-centric tools overlook.
The display-name and subject-line brand abuse that dominates real phishing gets caught. On live traffic, From-display-name spoofing alone out-volumes all domain-squatting techniques combined by ~40×.
What question it answers
Who's impersonating our brands? Are display-name attacks hitting us? What's the volume of CJK brand abuse?
Brand Protection answers these questions with a purpose-built detector that understands the tricks attackers use — and the language-specific variations that Western-centric tools miss.
Beyond domain watching
Traditional brand protection watches domain registrars. Real phishing happens in the From display name and subject line — 'Support' as the display name with a random freemail domain, or 'Invoice: ACME Corp' in the subject with no brand reference in the sender.
These techniques out-volume domain squatting by 40×. Brand Protection catches them.
Your own name is a brand too
The brand a BEC crew spoofs most is the recipient's own. Brand Protection derives every recipient's company identity from their domain on the fly — no list to maintain — and flags senders who claim that identity without being it: latin spellings, digit-stripped forms, katakana transliterations, and unicode look-alike dressing included.
Precision comes from an exception tree, not optimism: mail from the organisation's own domain, its DMARC-aligned senders, operator-listed personal addresses and confirmed in-thread replies are all exempt — and the symbols score as a nudge that combines with other signals, so a real employee writing from a personal mailbox doesn't get nuked.
Brand claims hidden in images
With the Vision module, a brand shown only in a message's images — a logo where no text filter can see it — reaches the same decision logic as text-based claims, with exactly the same exception tree. It scores as one combinable signal, not a model verdict.
When naming another brand is legitimate
A courier naming the retailer it delivers for is doing its job, not phishing — but whether a courier may speak for a retailer is a fact about the world, not about a message. An operator can mark a domain as authorised to name other brands; the permission only applies to mail that proves it came from that domain, and the suppression is never silent — the message records what would otherwise have been flagged.
At scale the console asks instead of assuming: when a sender names a brand not its own, the pair is put independently to two AI models from different vendors, and the sender is cleared only when both agree it has standing. A disagreement, a refusal or a failed call leaves the warning in place and puts the pair in front of a person — both answers side by side, in the models' own words. This was measured before it was built: on test sets from two different markets, the two models swapped places exactly, each vouching for fabricated relationships in the market the other knew — and the wrong answers carried the same confidence scores as the right ones. That is why no single model is trusted, why self-reported confidence decides nothing, and why bulk-mail platforms that send for anyone get no standing at all.
Your own vouch-or-refuse decisions outrank the models permanently and are recorded with who and why. A deployment that has been running for a year owns a brand-relationship list built from its own mail, in its own market — the thing nobody could have shipped to it.

Example: Display-name spoofing at scale
A financial services customer adds their brand to the protection list. Brand Protection surfaces 15,000 messages with 'Bank of America' in the From display name — but the sender domains are random freemail providers. Domain-based filters miss this entirely. The operator adds the display-name pattern to a map and blocks the entire campaign.











