CTP247PRE-LAUNCH

Coming soon.

CTP247 is cyber threat protection that never clocks out — autonomous agents watching your attack surface, brand, and the dark web 24/7. Leave your email and we'll let you know when it's live.

One email at launch. No newsletters, no marketing dripfeed.

CTP247

Email Security · DMARC360

Know exactly who sends as you.

Every mailbox provider that receives mail claiming to be you writes a report about it. Almost nobody reads them. CTP247's DMARC360 parses those aggregate reports continuously, scores your posture, and shows the spoofing campaign as a spike on a chart — not as a customer complaint.

Get a demoAll modules
EMAIL SECURITY · DMARC360 · SAMPLE LOGREC
[dmarc]aggregate report: 41,209 messages from 312 sources
[spf]fail spike: unknown pool 198.51.100.0/24
[dkim]selector s1 rotated · alignment holding 99.2%
[classify]campaign pattern: invoice-themed spoofing
[score]domain posture 87/100 · enforcement ready
[verify]TXT challenge confirmed for mail.acme.com

Aggregate report parsing

DMARC RUA reports from every major provider are ingested and parsed continuously — XML you'd never read becomes per-source, per-day sending analytics.

Posture scoring

SPF, DKIM, and DMARC configuration is scored per domain. You see which domains are at enforcement, which are stuck at p=none, and exactly what's blocking the next step.

Spoofing analytics

Authentication failures are clustered by sender pool. A new pool failing SPF at volume is a spoofing campaign in flight — visible the day it starts.

Legitimate-sender mapping

Marketing platforms, CRMs, ticketing tools — every legitimate third party sending as you is identified, so the path to p=reject doesn't break payroll notifications.

Domain verification

Domain ownership is proven via DNS TXT challenge before data flows, so reports and analytics only ever attach to domains you control.

Phishing classification

Suspected phishing pages are live-probed and classified by a pure-Python heuristic — and confirmed phishing infrastructure flows straight into brand takedowns.

How it works

01

Point your RUA at CTP247

One DNS record per domain sends your aggregate reports to the platform. Domain ownership is verified by TXT challenge first.

02

Reports become analytics

Every report is parsed into per-source rows: who sent, how much, what passed SPF and DKIM, what aligned. History accumulates from day one.

03

Separate signal from noise

Legitimate senders get identified and grouped; unknown pools failing authentication get clustered and scored as potential spoofing.

04

Walk to enforcement

With every legitimate sender accounted for, you tighten policy — none, quarantine, reject — per domain, with data showing it's safe at each step.

05

Feed the takedown loop

Spoofing infrastructure identified here joins the same case fabric as brand hits — investigated, documented, and taken down through the same adapters.

Under the hood

INGESTDMARC aggregate (RUA) report parsing, continuous
ANALYSISSPF, DKIM, DMARC evaluation and alignment per source
SCORINGPer-domain posture score with enforcement readiness
DETECTIONFailure clustering by sender pool; campaign identification
VERIFICATIONDNS TXT challenge before any domain data flows
CLASSIFICATIONHeuristic phishing classifier, swappable ML backend
INTEGRATIONFindings flow into alerts, cases, and takedown adapters
REPORTINGPosture trends and campaign history, exportable