Coldfeet
Features

Everything Coldfeet does to a message

From the moment mail arrives to the audit record left behind — scanning, policy, delivery and evidence, in one place.

Inspection

What happens to every message

Engines run in parallel on the full message, not on a sample, so no single signal decides a verdict on its own.

Malware and attachment analysis

ClamAV plus signature feeds on every attachment, with archives unpacked and inspected rather than skipped.

Spam and content scoring

Rspamd scoring combined with content and intent analysis, so a clean-looking payment request is still caught.

URL reputation and rewriting

Links are checked against reputation feeds and can be rewritten so a click is evaluated at the moment it happens.

Authentication verification

SPF, DKIM, DMARC and ARC are verified on arrival, and the result is recorded in the message trace.

Impersonation defence

Display-name and lookalike-domain checks against your own directory, which is where BEC usually starts.

Data loss prevention

Pattern and dictionary matching on outbound mail, so regulated data does not leave in an attachment.

Control

Policy you can change safely

A rule that cannot be tested is a rule nobody dares change, so every policy can be validated before it acts on live mail.

Per-tenant policy engine

Conditions on sender, recipient, content, verdict and authentication, with actions from tag to reject.

Validate before apply

Run a draft rule against recent traffic and see exactly which messages it would have changed.

Versioned and reversible

Every policy change is versioned with its author, so a bad rule is one rollback away.

Quarantine and release

Admin and end-user quarantine with digests, one-click release, and sender allow and block lists.

Evidence

Answers when someone asks what happened

Delivery, retention and audit are part of the product rather than an add-on, because that is what an incident actually needs.

Full message trace

Every engine result, the policy that matched, and per-recipient delivery status for each message.

Archive and eDiscovery

Searchable retention with export, so a legal hold does not require reading mail server logs.

Tamper-evident audit log

Every administrative action is recorded with actor, tenant and before-and-after state.

Reporting and DMARC

Scheduled reports, DMARC aggregate ingestion and a sending-source inventory for the enforcement journey.

Use cases

Built for the people who own the mail flow

The same platform, pointed at whichever problem you are actually being measured on.

Security teams

Stop the attacks that clear authentication

Payment fraud and supplier impersonation pass SPF and DKIM cleanly. Intent analysis and lookalike-domain defense are what catch them.

  • BEC and impersonation detection
  • Attachment and URL detonation
  • Threat trends by sender and tenant
IT operations

Run mail security without a migration project

Keep the mailboxes you have. Add scanning in front of them, and get the queue, spool and delivery visibility you never had.

  • Guided DNS with live verification
  • Continuity spool when a destination is down
  • Per-recipient delivery status
MSPs and resellers

One console, every customer, your name on it

Tenants are isolated by design, and branding, policy and reporting are all per tenant — so the platform can be sold as your own.

  • White-label branding per tenant
  • Tenant export and transfer between installs
  • Delegated admin with scoped roles
Compliance and risk

Answer the audit with evidence, not assurances

Retention, archive search and a tamper-evident audit trail mean the answer to "what happened to this message" is one query.

  • eDiscovery search and export
  • Immutable audit log of every admin action
  • DMARC reporting and enforcement journey

See it against your own mail

Point a single domain at Coldfeet and compare what it catches with what you have now.