By the time the link is blocked, it has already been read.
The blocklist catches up in hours. The click happens in the first minute. In between there is one layer: the person reading.
The banner is real output. Flip the switch to see the same message as delivered.
20260806247242 – Request for Quote
Good morning,
We are requesting a quotation for an upcoming project that aligns with your area of expertise.
Please review the attached document for the required item details and quote information needed to submit a compliant response. We kindly request your completed quote by close of business Friday, if possible.
Please include the RFQ number in the subject line of all correspondence.
Thank you, and we look forward to your response.
Meredith Keller
Office Manager, Lakeshore Dental Group
X-ToneGuard-Risk: highX-ToneGuard-Signals: attachment.link_lure,attachment.name_content_mismatch,sender.undisclosed_recipientsX-ToneGuard-Version: 1 60 attachment.link_lure 55 attachment.name_content_mismatch 20 sender.undisclosed_recipientshow long the linked sites have existed was not checkedmessage wording was not analysedReported, never counted as a clean result.Reconstructed from a message that reached a live mailbox on 9 August 2026 and scored clean at the time. The body holds no link at all — a filter that checks links had nothing to check. The file, its seven words and its destination are the ones that arrived; the parties are replaced.
Every other layer does its job outside the minutes that decide it.
Nothing here failed. The gateway made a fair call; the blocklists caught it once known. The campaign is built for the gap between.
- 07:02
Delivered
Registered days ago, no history, no reports. Nothing for a filter to hold against it.
- 07:09
Read
Mail is read on arrival. The page is live, the deadline says today, the summary above has already agreed.
- 07:10
Credentials entered
One minute of ordinary compliance. Then a forwarding rule, a changed deposit account, a campaign sent from your own domain.
- Next afternoon
Pulled back
Zero-hour auto purge removes it once the verdict catches up. Documented case: delivered 7:03 PM, pulled 2:35 PM the next day — 19½ hours readable. Your quarantine log has this pattern.
- Days later
Blocked
DNS filters and Safe Browsing now stop the page cold. All correct. None early.
- Later still
Taken down
By the time anyone investigates, the page is gone — with any way of showing the student what they typed into.
ToneGuard runs inside the window. The warning is on the message before the reader is, while the page is still live.
The assistant read the attacker's email and wrote it into a to-do list.
Summarising is not checking. The assistant restates what a message claims — authority, deadline, consequence — above the message, before the reader has formed a doubt.
“Due today — Verify your 2026–27 aid disbursement details. Verification is needed for all aid recipients, including scholarships and grants.”
Confident, well organised, correctly formatted, and sourced entirely from a stranger.
accounts.aid-verify.icu/session?u=YS5raW1A…
A summary reads words. It does not open the link, check the domain, or notice the reader's own address already sitting in the query string.
A stranger's deadline, promoted to an item on their own list, with a reminder button beside it.
Scepticism has to start somewhere. It does not start under a heading that says the task is due today.
This lands hardest on students — aid disbursement, tuition refunds, first-job payroll — aimed at someone genuinely waiting for that exact email.
Not a score. Evidence.
Every warning carries what triggered it: the sentence, the address, what the destination turned out to be. A number teaches nothing; evidence carries to the next message.
Pretext analysis
Names the manipulation — urgency, authority, consequence — and quotes the sentence that does it, instead of describing it in the abstract.
The destination is opened first
Links — and attached files — are opened in a single-use isolated machine before you are warned. The verdict is based on what the page is, not what its address looks like.
Campus threat digest
What ToneGuard saw across campus, clustered into a warning your IT staff review and send in their own voice.
ON THE ROADMAP — NOT SHIPPING TODAY, AND WE SAY SOThree console steps, and no change to how your mail is delivered.
No MX change, no mail-flow rule, no agent, nothing for a student to install. Your admin grants access in your own console — and revokes it there.
Your admin grants access
Google: domain-wide delegation, two scopes. Microsoft 365: admin consent, then a policy scoping it to the mailboxes you name. Two minutes, in your console.
You name the mailboxes
Enrolment is per mailbox, never implicit — a granted tenant is not a scanned one. Start with finance and procurement; widen once you have watched it work.
The warning arrives with the mail
A minute after delivery, the message carries the banner. The original is archived and kept — no permission here can delete mail.
Read the full install runbook — every console step, every permission, and what we deliberately never ask for. It is the same page your admin gets after checkout.
There is no add-on, on either platform.
Nothing in any marketplace, nothing installed, no ToneGuard account for anyone to phish. The warning is in the message, and the message is already in their inbox.
Where this sits in a stack that is already good.
ToneGuard is not a filter, a gateway, or a replacement for anything you run. It covers one interval no other control is positioned to cover: after delivery, before the infrastructure is known.
Decide whether a message is delivered at all. ToneGuard begins after that decision and never argues with it.
Cover the infrastructure once it is known to be bad. Excellent coverage; the timing belongs to whoever reported it first.
Teaches in advance, about a message that is not this one. ToneGuard is the same lesson attached to the message in front of them, at the second it applies.
Starts when somebody reports. Evidence in the reader's hands is what makes the report arrive — while the page is still up.
The failure mode we engineered against is banner fatigue.
You already run a warning nobody reads: the external-sender tag, on everything, invisible within a month. Attention is earned with silence, so the deployment enforces a contract on itself:
- Quiet is the default.Below the warning threshold nothing is added — no banner, no label, no “scanned by” footer. Most mail, most days, is untouched.
- The design point is under half a percent. Fewer than one scanned message in two hundred should earn a banner. A banner is an event, not furniture.
- The alarm points at us, not at the mail. A live banner rate of four times the design point alerts the operator — an alarm, never a limiter, because a real campaign must banner every copy it lands.
- The pilot report grades us against it. The measured banner rate beside the design point, and every warning we got wrong, counted. You see our error rate without having to ask for it.
What it does not do
- It blocks nothing. It cannot stop a click, quarantine a message, or rewrite a link. It puts evidence in front of a person and the decision stays theirs.
- Nothing about mail delivery depends on us. ToneGuard sits out of band — if it is down, mail is delivered exactly as it is today. The failure mode is unscanned messages, never undelivered ones.
- It does not replace your gateway, and a pilot that removes one is not a pilot we will help you run.
- There is no dashboard. The exposure report is a document we produce from the audit log and hand you — not a portal, not a live feed. The campus threat digest is on the roadmap, not on the invoice, and will not be demonstrated to you as though it were.
- A check that could not run is reported as unavailable — never quietly counted as a clean result.
What procurement will ask
- Permissions
- Google: gmail.modify + gmail.insert, delegated by you. The full mail scope is never requested, so nothing here can permanently delete mail. Microsoft: Graph Mail.Read + Mail.ReadWrite, which we ask you to scope with an application access policy.
- Data
- Message bodies are never stored. The audit log records the outcome and which checks fired, as identifiers — never their contents, never a mailbox address. Link screenshots expire in thirty minutes.
- Deployment
- A console grant and a list of mailboxes. No student action, no endpoint agent, no MX or mail-flow change — and the banner is inserted into the body, which privacy accounts for exactly.
- Audit
- Every scan is recorded as outcome, risk level and detector identifiers — never message content, never a mailbox address. Your exposure report is built from that log, not from a separate telemetry pipeline.
- Review
- HECVAT-mapped assessment answers and the full data-handling document before you pay — written with the unflattering facts first, each claim cited to the code that enforces it.
- Commercials
- Per protected mailbox — you pay for the mailboxes you cover, not the ones you might. See pricing.
Three sentences ToneGuard is built to never say.
Security tools earn trust by what they refuse to claim. These refusals are enforced in code, not promised in policy.
Run it on the twenty mailboxes that are actually being hunted.
Finance, procurement, payroll, the president's office. Thirty days, nothing in your mail path. At the end you hold the number nobody else can give you: what got through, what we warned on, how often we were wrong. The report is yours either way.