Email Protection

When an email isn't from who it says.

In Gmail and Outlook, Haven reads the message the way an attacker built it. If it wears a brand's name but its links go somewhere that brand does not own, Haven says so at the top of the email, before you click anything.

What you'll see

One message, one signal, never a pile of them

Impersonation is the attack Haven is built for, whether it wears a company's name or a colleague's. Haven shows exactly one thing per email, and a warning always outranks a reassurance, so a message can never be flagged and praised at the same time.

Impersonation

A brand you trust, or a person you know

The name says one thing and the message says another. A bank or payment service whose links lead off its own domains, or a colleague's name above an address from outside your company. Haven flags the gap and shows you where the link really goes.

“Link claims northpeak.example but goes to a different domain”
Suspicious links

A link inside doesn't hold up

No brand involved, just a link that failed on its own. The banner always names the reason, so you know whether it was a lookalike domain, a mismatched destination, or a redirect that lands somewhere unexpected.

“Haven detected suspicious links in this email”
High pressure

The language itself is the tell

Some phrases are so specific to scams that Haven warns on them even when every link is clean. Deliberately a very short list, because the cost of crying wolf on ordinary mail is high.

“This email uses high-pressure language commonly found in scam emails”
Verified sender

We can tell you who sent it

A small chip beside the sender when the sending domain really does belong to the brand it claims. It names the domain rather than passing judgment, because knowing who sent something is not the same as knowing it's harmless.

“Verified, really northpeak.example”
Checked

Proof it looked, even when nothing's wrong

Most mail is ordinary, and Haven still checks every link in it. A quiet chip says so, reporting the work rather than passing a verdict.

“Haven checked the links here”

Every banner can be dismissed, and each one carries a thumbs up and thumbs down. If Haven gets a message wrong, one click tells us, and that feedback is what the detection improves on.

How it decides

Impersonation is a mismatch, not a word

Plenty of ordinary email mentions a brand. It counts as impersonation only when all three of these are true at once.

01

A brand is named

The body invokes a known brand. A name that appears only as link text pointing at that brand's real site is discounted, because that is a signature.

02

The sender isn't it

The sending domain is checked against the ones that brand really sends from. A match ends it. A brand name in the display field with no matching domain counts against the message.

03

The links go elsewhere

Links are unwrapped past trackers and redirects, then checked against the brand's real domains. All of them leading somewhere else is the strongest signal Haven has.

Urgency sits underneath all three. Pressure language lowers Haven's tolerance for a questionable link, but never flags on its own. Plenty of real mail is genuinely urgent.

Worth saying plainly

Verified means we know who, not that it's safe

“Verified, really northpeak.example”

The chip states an identity: this really did come from the domain it claims. It will never say a message is safe, because a real company can send you something you shouldn't act on and we'd have no way to know.

Two things Haven doesn't do. It doesn't open or scan attachments, so an unflagged one is unexamined, not cleared. And it never deletes, moves, or blocks anything. It adds a banner and leaves the rest alone.

Where it works

In the inbox you already use

Email Protection runs inside the Haven browser extension, on the mail you read in your browser. There is no mailbox to connect and no account access to grant.

Gmail

Personal Gmail and Google Workspace at mail.google.com, including threaded conversations, where each message is assessed separately.

Outlook

Outlook on the web at outlook.live.com, outlook.office.com, and outlook.office365.com, covering personal accounts and Microsoft 365.

Answers to Your Questions

Get answers to commonly asked questions about Haven's email protection.

Contact us
Haven analyzes a message in your browser while you have it open in Gmail or Outlook, checking the sender, the wording, and where each link actually leads. It is not a mailbox connection: Haven does not sign in to your email account or request access to it. For what is recorded, see Haven's privacy policy.
Gmail, including Google Workspace accounts, and Outlook on the web, covering personal Outlook accounts and Microsoft 365. Haven runs in the browser, so it works with webmail rather than desktop mail applications.
It means the message genuinely came from a domain that belongs to the brand it claims to be. It is a statement about identity, not safety. Haven deliberately does not use it to say an email is safe, because a legitimate sender can still send you something you should not act on.
No. Haven does not open attachments, inspect their contents, or check them against a malware database, and it is not a replacement for antivirus software. An attachment Haven has not flagged should be treated as unexamined rather than confirmed safe.
Yes, when your team is set up in Haven. If a message carries a teammate's full name in the sender field but arrives from a domain outside your organization, Haven flags it and shows both the sending address and that person's real address side by side. Messages from a colleague's genuine address, including registered aliases, are never flagged this way.
No. Haven adds a banner to the top of the message and leaves it in place. Nothing is deleted, quarantined, or moved, and you can still open and read anything Haven flags. Banners can also be dismissed if you disagree with them.
Detection weighs several signals at once, and a legitimate message that mentions a brand while linking to a third-party service can occasionally look like the pattern Haven watches for. Every banner carries a thumbs up and thumbs down, and marking it as fine both dismisses it and feeds back into improving detection.
No, it works after that filter. Spam filtering decides what reaches your inbox at all. Haven adds a second look at what did reach it, in the browser at the moment you are reading, which is where phishing that survived the filter is actually encountered.
Yes. Email Protection is included with Haven, which is free for individual use. There is no separate charge for it and no trial period. Teammate impersonation detection requires a team set up in Haven.