Customs is a second set of eyes on every invoice, payment request, and login email. It reads each one the way a security analyst would — then tells you, in plain English, whether it's safe to act on.
Customs flagged this email — MALICIOUS (95% confidence)
A banking change from an unverified domain. Call your Apex Supplies contact on a number you already have before paying anything.
AS
Apex Supplies Accounts
<accounts@apex-supplies-billing.com>
Customs: Malicious
Updated bank details — please use for invoice #4821
Hi, Please note our remittance details have changed effective immediately. Kindly update your records and process invoice #4821 ($12,840.00) to the new account:
Routing 091000022 · Account 7702318854
Regards, Dana Whitfield · Accounts Receivable
Customs verdict
✕ Malicious95% confidence · score 102
Why it was flagged — in plain English:
vendor impersonation+50
Apex Supplies is a vendor you pay — but their real domain is apex-supplies.com. This came from apex-supplies-billing.com, a cousin domain built to look right.
banking-change request+40
Asks you to redirect payment to a new bank account — the core of business email compromise. Customs always treats a vendor + new-bank-details combination as hostile until verified.
first contact+12
This exact sender has never emailed your team before.
Why this matters: the fake-vendor banking change is the single most expensive email scam for U.S. businesses (the FBI logs billions in BEC losses every year). Customs catches it because it knows which vendors you actually pay — and which domains are really theirs.
⚠ What lands in the inbox
⚠
Customs flagged this email — MALICIOUS (99% confidence)
Don't click links or reply — the brand doesn't match the authenticated sender. Verify by phone if it's about payment or login.
lC
lCIoud Support Team via greytHR
<recruit@notifications.greythr.com>
Customs: Malicious
Complete Verification Immediately
Hello [email protected], This is the final reminder that you are required to complete your iCloud verification immediately. Failure to complete will result in loss of Photos, Mail, Notes, Contacts and more. Verify Now →
Customs verdict
✕ Malicious99% confidence · score 85
Why it was flagged — in plain English:
brand impersonation+45
Claims to be iCloud, but was sent from notifications.greythr.com (not apple.com / icloud.com).
auth misalignment+30
Passes email auth — but for greythr.com, not iCloud. A valid signature ≠ a legitimate sender.
urgency / credential+10
Pressure language (“verify immediately,” “final reminder”) typical of credential phishing.
This one is real: it's the first phish Customs ever caught in production — it had already sailed past Microsoft's filters because, technically, nothing about it fails authentication. The mismatch between the brand and the authenticated sender is what gives it away.
✓ An everyday invoice — left untouched
CB
Contoso Billing
<billing@contoso.com>
Contoso receipt #CUSTPYMT641659
Hi — thanks, your payment of $956.92 was received. Your receipt is available in the billing portal: app.contoso.com/billing. No banner, no label — a legitimate email is left exactly as it arrived.
Customs verdict
✓ Clear90% confidence · no signals
No red flags found — safe to act on. (Not a guarantee; Customs re-checks if anything changes.) What it verified:
sender authenticated
SPF, DKIM and DMARC all pass and align with contoso.com — the vendor's real domain.
known vendor
Matches a vendor you actually pay; no lookalike domain and no banking-change request.
links clean
The only link goes to contoso.com — no redirect, shortener, or text/destination mismatch.
Just as important: Customs leaves real mail alone. No quarantine purgatory, no second-guessing every receipt — your team only hears about the mail that deserves a second look.
Protect your inbox in minutes.
Free for one inbox. Upgrade when you want Customs to label, move, and digest automatically. Cancel anytime.