Glossary

Email security,
in plain language.

The vocabulary of email threats and defenses — grouped by theme, written to be understood on the first read.

37
terms, defined in plain language
4
themes — attacks, defenses, standards, Doorcheck concepts
0
pieces of jargon left unexplained

The attacks

Phishing
Email that manipulates the recipient into clicking, paying, or handing over credentials. Modern phishing is often polished, personalized, and free of obvious red flags.
Spear phishing
Phishing aimed at one specific person, using details about their role, colleagues, or projects to look authentic.
Whaling
Spear phishing aimed at executives — the accounts with the authority to move money and unlock doors.
Business email compromise (BEC)
An attack that abuses business trust rather than malware: a wire request, changed bank details, an urgent favor from “the CEO”. Usually payload-less.
Vendor email compromise (VEC)
BEC through a supplier: attackers compromise (or imitate) a vendor you already trust, then redirect a real payment flow.
Account takeover (ATO)
An attacker controlling a legitimate mailbox. Every technical signal looks right — only the behavior is wrong.
Impersonation
Pretending to be a trusted person or brand via display names, lookalike domains, or hijacked threads.
Lookalike domain
A domain crafted to pass a glance: rnicrosoft-online.com, workdaay-app.com. One letter is doing all the work.
Thread hijacking
Replying inside a real, existing conversation from a compromised account — inheriting all of its trust.
Payload-less attack
A malicious email with no link and no attachment — just a request. Nothing for a scanner to detonate; everything for context analysis to catch.
Quishing
Phishing via QR code: the malicious URL hides in an image, out of reach of link scanners — and gets opened on an unmanaged phone.
Credential harvesting
Fake sign-in pages that collect usernames, passwords, and MFA codes — the raw material for account takeover.
AI-generated phishing
Lures written by language models: fluent, personalized, error-free, and produced at scale. Kills the “bad grammar” heuristic for good.
Campaign
One attack, many copies: the same lure pattern landing across dozens or thousands of mailboxes, often mutated to evade signatures.
Graymail
Mail that isn’t malicious but nobody wants — newsletters, cold outreach, notification noise that buries real threats.

The defenses

Behavioral AI
Detection based on how people and organizations actually communicate — relationships, habits, payment patterns — rather than static rules and signatures.
Communication graph
The learned map of who talks to whom, how often, in what tone, about what. The baseline that makes “this doesn’t belong” computable.
API-based email security
Protection that connects through the mail provider’s API instead of sitting in the delivery path. No MX changes; disconnecting it can never break mail.
Secure email gateway (SEG)
The traditional approach: a relay in front of your mail server that scans messages in transit. Strong on known-bad; weak on attacks that look legitimate.
Quarantine
A holding area for suspicious mail — intact, searchable, releasable. Not a trash can.
Purge / recall
Removing every copy of a confirmed threat from every inbox it reached — in Doorcheck, always into quarantine, never deletion.
Auto-triage
Letting the system investigate user-reported mail: verdict, campaign lookup, remediation, audit entry — no analyst required for the routine cases.
Phishing simulation
Controlled fake phishing sent to your own staff to measure who clicks — and to aim coaching at exactly those people.
Just-in-time coaching
Training delivered at the moment of the mistake, to the person who made it — instead of annual courses for everyone.
False positive
A legitimate message flagged as a threat. The real cost of security tooling — which is why release must be one click and a learning signal.

The standards

SPF
A DNS record listing which servers may send mail for a domain. Necessary, but attackers pass it with domains they own.
DKIM
Cryptographic signing that proves a message wasn’t altered and really came from the signing domain.
DMARC
The policy layer over SPF and DKIM: what receivers should do when authentication fails. Stops exact-domain spoofing; says nothing about lookalikes.
MX record
The DNS entry that routes a domain’s mail. Gateway products require changing it; API-based products don’t touch it.
OAuth scopes
The specific permissions an app requests from your mail provider. Least-privilege scopes are a security product’s honesty test.
Zero trust
The principle that nothing is trusted by default — including, in email, senders you’ve trusted for years.

Doorcheck concepts

Check the door
The Doorcheck model in three words: verify that an email belongs before anyone trusts it.
Sovereign AI
Running the detection models on your own hardware — self-hosted, air-gap friendly — so message content never leaves your infrastructure.
Cross-tenant intelligence
One attack, learned once, protecting many: campaigns detected in one tenant inoculate every other tenant within minutes.
AI failover
Multiple AI providers with automatic failover and local classifiers as the last line — a verdict is always produced, even with every provider down.
Token optimization
Prompts engineered so the AI reads only what a verdict needs — keeping decisions fast and inference costs flat at fleet scale.
Verdict
Doorcheck’s decision about a message — legitimate, suspicious, or threat — with the reasons attached and an audit entry behind it.

Don't trust the email. Check it.

Connect your existing mail in minutes — no MX changes, sovereign self-hosted option, free during beta.

Get early access