Use cases

Built for the attacks
you actually face.

Doorcheck earns its seat by handling the scenarios that cost real money and real analyst hours — the ones that look legitimate until it’s too late.

1
click to purge a whole campaign from every mailbox
3
detection layers — rules, local classifiers, LLM reasoning
0
emails deleted — everything recalls to quarantine
24/7
auto-triage of user-reported mail, no analyst required

What a missed email costs

The use cases below aren't hypothetical — they're the categories behind the industry's ugliest numbers.

$2.8B
in BEC losses reported to the FBI's IC3 in 2024 alone
#1
phishing is the most-reported cybercrime category (FBI IC3)
68%
of breaches involve the human element (Verizon DBIR 2024)
<60s
median time for a user to fall for a phish after opening it (DBIR)

Sources: FBI IC3 Internet Crime Report 2024 · Verizon Data Breach Investigations Report 2024.

See it before you engage it

Doorcheck ships with two operating modes. Start in monitor, judge the verdicts on your real mail, and flip to enforce only when you're convinced — with every mailbox owner kept in the loop.

Monitor mode
Verdicts only — mail untouched
Every message is scored and every would-be quarantine shows up in the console and reports, but nothing is moved and nothing changes for your users. It's a live proof-of-value on your own traffic: you see exactly what Doorcheck would have caught — and what it would have left alone — before it acts on a single email.
Zero risk. Full visibility.
Enforce mode
The same verdicts, now acting
One toggle — per tenant, even per policy — and confirmed threats are recalled to quarantine automatically, campaigns are purged fleet-wide, and takeover signals raise incidents. Every action is audit-logged and one click reverses a wrong call, so turning it on isn't a leap of faith.
Flip the switch when the verdicts have earned it.
Mailbox reports
Every mailbox sees what was blocked
Each mailbox owner gets their own digest of what Doorcheck held back and why — in plain language, not verdict codes. Nobody wonders where an email went: they check the report, and if something legitimate was caught, they release it themselves in one click.
Security that explains itself.
Operator summary
One view for the people running it
Admins and MSP operators get the fleet-wide picture — verdicts, campaigns, releases, and per-tenant trends — in the console and on a schedule in their inbox. The same numbers your users see, aggregated for the people accountable for them.
No black box. No blind spots.

Day one with Doorcheck

From "let's evaluate it" to "it's protecting us" — before the first coffee refill.

09:00 — CONNECT
OAuth in
Admin consents to the scoped permissions in Microsoft 365 or Google Workspace — or points Doorcheck at Exchange, cPanel, or IMAP. No MX changes, nothing to reroute.
09:14 — PROTECTED
Verdicts flowing
The AI starts scoring inbound mail immediately and begins learning your communication graph — in monitor mode first if you prefer, so you watch the verdicts before it acts. The console lights up either way.
WEEK 1 — TUNED
Baseline learned
The graph now knows what "normal" looks like for your people and vendors. Simulations identify who clicks; coaching goes only to them.
Phishing
Stop phishing that looks legitimate
Polished, personalized, AI-written lures — with or without a payload. Doorcheck scores intent and context, not just links and attachments.
Less “does this look bad?” More “does this make sense?”
BEC
Stop BEC & executive impersonation
The wire request that sounds exactly like your CEO. Doorcheck knows how your executives actually write, pay, and ask — and flags the message that doesn’t fit.
The most dangerous email doesn’t look dangerous.
Vendor fraud
Catch compromised vendors
A real supplier account sends new bank details. Filters see a trusted sender; Doorcheck sees a payment pattern that never existed in years of invoices.
Trusted sender doesn’t mean trusted forever.
Takeover
Detect account takeover
Same mailbox, same signature, different behavior. Impossible-travel sign-ins, new reply-to addresses, and sudden tone shifts light up the graph.
When familiar starts acting unfamiliar, Doorcheck notices.
SOC automation
Auto-triage reported mail
User-reported phish investigate themselves: verdict, campaign correlation, fleet-wide recall, audit entry. Analysts handle judgment, not repetition.
Your inbox doesn’t need another alert. It needs an answer.
Campaigns
Purge campaigns everywhere
Find one malicious message and Doorcheck maps every related copy across every mailbox — then recalls them all to quarantine in one click.
Find one. Purge all.
Training
Train the people who need it
Simulations find who clicks; just-in-time coaching goes only to them. Security training follows risk — not a calendar.
Don’t train everyone for the mistakes of a few.
MSP
Protect many tenants from one console
Per-client policies, isolated data, fleet-wide campaign visibility. When one tenant is hit, every tenant is inoculated.
One door. Many customers.

Don't trust the email. Check it.

Connect your existing mail in minutes — no MX changes, sovereign self-hosted option, free during beta.

Get early access