Product · How it works?

An email’s journey, secured in four stages

DeepFilter runs every incoming message through a multi-layered defense chain across four stages: pre-analysis, deep inspection, evaluation and decision. Every layer’s score combines into one trust score, and the reason behind every decision is transparent.

How does it work?

Four stages, one trust score

Dozens of signals combine into a single trust score; every decision is transparent.

01

Pre-Analysis

The sender and the message pass a first screening across authentication, blocklist and statistical classification layers within seconds.

02

Deep Inspection

AI, central intelligence, signature matching and visual inspection layers examine the message in depth.

03

Evaluation

Scores from every layer combine into one trust score; the mail is classified as clean, suspicious or dangerous.

04

Decision

Email that clears the trust threshold is delivered to the recipient; the rest is quarantined.

Detection layers

Not a single spam filter, a layered defense

SPF/DKIM authentication and scenario-based policy, blacklist queries, statistical classification, AI-assisted detection, similarity analysis, antivirus and phishing detection combine into one trust score across seven layers. Borderline mail is marked "suspicious".

SPF / DKIM authentication Blacklists (RBL/URIBL) AI-assisted detection Statistical classification Similarity analysis Antivirus + signed feed Phishing engine
QUARANTINE Total score +114.0 · threshold 12
DeepFilter RBL Policy Decision
DEEPFILTER_POLICY_RBL · Reputation / Blocklist
+25
DeepFilter SPF Fail Policy
DEEPFILTER_POLICY_SPF_FAIL · Authentication
+25
HELO Verification Hard Quarantine
HARD_QUARANTINE_HELO_FAIL · Technical
+25
DeepFilter AI: SPAM
DEEPFILTER_AI_SPAM · prob=0.9887 · AI
+10
Spamhaus XBL
RBL_SPAMHAUS_XBL · Reputation / Blocklist
+4
At every stage

What happens to each message

The tools behind the four-stage chain; all running on your own server.

Authentication

SPF/DKIM verification with scenario-based policy; outbound DKIM signing.

Reputation / blacklists

RBL/DNSBL/URIBL queries with open-resolver false-positive protection.

AI + statistical

AI-assisted detection and statistical classification working together.

Similarity analysis

Body shingle and visual similarity match a message against known spam signatures.

Antivirus

ClamAV plus a centrally signed up-to-date feed; viruses stay quarantined.

Attachment control

Block executable/risky attachment types inbound and outbound.

Quarantine management

Admin filters/audit + end-user magic-link portal.

Delivery & routing

Domain-based routing, smarthost/relay, queue tracking and retry.

Explainable scoring

400+ rule knowledge base showing why each message scored.

See the defense chain on your own traffic

We set up a guided POC on your existing infrastructure and walk you through every stage.

4
stages, one trust score