Threat protection

Layered defence against every email threat

Spam, malware, phishing, business email compromise and account takeover each need a different defence. mxflo runs all of them — inbound and outbound — and shares intelligence across the whole fleet.

Multi-engine AV Click-time URL defence Anti-BEC DMARC / DKIM / SPF UEBA Compromise containment
Multi-engine antivirus

Three engines. One verdict.

A single antivirus engine always has blind spots. mxflo scans every message and attachment with three — ClamAV plus Check Point and Bitdefender via ICAP — so a threat missed by one is caught by another. You can even see which engine caught what, to measure the value of each licence.

  • ClamAV, Check Point ICAP and Bitdefender ICAP in parallel
  • Attachment, archive and macro heuristics
  • Per-engine detection reporting for licensing ROI
Message scan resultMalware blocked
ClamAVclean
Check Point ICAPTrojan.Generic
Bitdefender ICAPclean
VerdictQuarantined
Display-name checkHeld: phishing
Display name"CEO — Jane Doe"
Actual senderjane.doe@look-alike.co
Protected identityMatched
ActionHeld for review
Anti-phishing & BEC

Stop the attack that has no payload

Business email compromise skips malware entirely — it's a convincing message from a fake "CEO" or a look-alike supplier. mxflo defends the human layer with impersonation detection, external-sender banners and authentication-aware spoof checks.

  • Executive & display-name impersonation detection
  • Look-alike and forged-sender identification
  • Click-time URL protection against credential-harvest links
  • External-sender warning banners
Authentication

Lock down who can send as your domains

Email authentication is the foundation of anti-spoofing. mxflo makes DMARC, DKIM and SPF observable and enforceable — without breaking legitimate mail.

DMARC visibility

Aggregate reports are ingested and charted so you can move to p=reject with evidence, not guesswork.

DKIM health & drift

Keys are signed centrally and continuously audited, so a rotated or missing key is caught before mail starts failing.

SPF alignment

Keeps SPF covering the correct egress IPs across a multi-edge deployment so outbound never trips a receiver's checks.

UEBA · account takeover

Behavioural analytics stop account takeover

The fastest way to wreck a hosting reputation is one compromised account sending spam for an hour. mxflo applies User & Entity Behaviour Analytics to email — baselining how every mailbox and entity normally behaves, then watching outbound behaviour and login telemetry together — and can shut the account down the moment it deviates, reversibly and with a complete evidence trail.

  • Per-entity behavioural baselines — volume, timing, recipients & content
  • Login analytics: brute force, password spray & impossible travel
  • Real-time risk scoring with reversible escalation (watch → throttle → hold → suspend)
  • Automatic cPanel / Zimbra suspension with incident report
Incident timelineContained
10:02Watch — volume spike
10:03Throttle — spam rate 0.6
10:03Hold — login from 20 IPs
10:04Suspend + alert & report

Put layered protection in front of your mail

We'll assess your current exposure and scope a rollout — inbound first, outbound when you're ready.