Category: Uncategorized

  • What Is Vishing? Voice-Phishing Scams Explained

    What Is Vishing? Voice-Phishing Scams Explained

    Vishing is voice phishing. It's a phone scam where criminals call you, pretend to be someone you trust, and try to get your personal or financial information. According to CrowdStrike's 2025 Global Threat Report, vishing attacks surged by 442% in 2024. In Canada, voice-phishing scams are among the fastest-growing fraud tactics, with the Canadian Anti-Fraud Centre reporting that Canadians lost over $704 million to fraud in 2025 across all categories.

    You've probably seen the setup before. Your phone rings, the caller ID says your bank, the CRA, or a local number, and the person sounds calm, confident, and urgent. They say there's a problem with your account, a tax issue, or suspicious activity that needs to be fixed right away.

    That's why this scam works. It doesn't rely on hacking your device first. It relies on pushing you to act before you stop and verify.

    At Typewire, we think awareness is still your best defence. Once you know the pattern, vishing gets much easier to spot.

    Last updated: 16 July 2026

    What is vishing?

    Your phone rings during a busy afternoon. The screen says your bank, the CRA, or a nearby number. The person on the line sounds calm and official, and they want you to confirm a few details “for security.”

    That call may be vishing.

    Vishing is short for voice phishing. It is a phone scam where someone uses a call, or sometimes a voicemail callback request, to pressure you into sharing personal information, banking details, login codes, or money. The method is simple. Instead of breaking into your device, the scammer tries to talk their way past your judgment.

    A woman looks concerned at her phone during an incoming call from a potential vishing scammer.

    The basic idea behind voice phishing

    Vishing is a form of social engineering. That means the attacker is targeting human trust, not just technology. A convincing voice, a spoofed caller ID, and a stressful story can make an ordinary phone call feel legitimate.

    In Canada, the familiar names matter. Scammers often pretend to be the CRA, a bank, a telecom provider, or technical support because those organizations already have a place in your daily life. A fake call about taxes or an account problem can feel believable before you have time to slow down and check.

    Practical rule: If an unexpected caller asks for your password, PIN, one-time verification code, remote access, gift cards, or an immediate payment, treat the call as suspicious.

    Why this matters in Canada

    For Canadians, CRA impersonation scams are a common example because they tap into a specific fear. People worry about tax problems, missed payments, or penalties. Scammers use that anxiety to push for quick decisions, such as “verifying” your identity or paying on the spot.

    There is also a privacy angle. If a vishing scammer gets your personal information and it is later mishandled by a business, Canadian privacy obligations under PIPEDA may come into the picture. For individuals, that means stolen details can cause more than a one-time loss. For small businesses, it is a reminder that phone-based fraud can turn into a customer data issue.

    The safest habit is straightforward. If a call is unexpected and the caller wants sensitive information, hang up and contact the organization yourself using the number on its official website or on the back of your card. Awareness is your best defence, and with vishing, that pause is often enough to break the scam.

    How voice phishing works

    Most vishing calls follow a script. Once you understand the steps, the scam feels less mysterious and a lot more predictable.

    A diagram illustrating the five-step process of voice phishing, showing how scammers trick victims over the phone.

    The call starts with trust

    The first trick is presentation. The number may look local. The caller ID may show the name of a bank or government office. That's often possible because scammers can spoof caller ID, which means they can make a call appear to come from a number you recognise.

    Then comes the story. The caller might say there's suspicious activity on your account, a tax debt, a service interruption, or a login problem that needs immediate attention. Their actual goal is to stop you from slowing down.

    CrowdStrike notes in this guide to vishing attacks that scammers often rely on fear, such as threats of arrest, or urgency, such as an account problem. The same source also warns that some attackers already have partial information from data breaches and use it to convince you to reveal the rest.

    Why partial information feels convincing

    This confuses a lot of people. They think, “How could it be fake if the caller knew my name, address, or email?” The answer is simple. Knowing a few details doesn't prove the caller is legitimate.

    A scammer might know your name from a public profile. They might know part of your phone number, company, or address from an old breach or online listing. They use those fragments like props in a play.

    If a caller knows something about you, that should raise your caution, not lower it.

    Later in the call, the ask becomes more direct. They may request a one-time passcode, a login, your debit card details, or payment. Cisco's explanation of what vishing is and what attackers want makes the main goal clear: to steal private data for identity theft, financial gain, or account takeover.

    Here's a short video if you want to see how these scams are commonly explained in practice.

    A typical attack flow

    1. You get an unexpected call from someone claiming to represent a trusted organization.

    2. The caller creates pressure with a problem that sounds urgent.

    3. They build credibility by using your name or other partial details.

    4. They ask for sensitive information or payment.

    5. You're pushed to act immediately so you won't verify the story independently.

    Once you see that pattern, the call becomes easier to interrupt. You don't have to win an argument with the scammer. You just have to stop the conversation.

    Real vishing examples

    The easiest way to recognise vishing examples is to hear how they sound in real life. These calls usually feel ordinary at first. The pressure comes a few seconds later.

    The fake CRA call

    You answer, and the caller says they're from the Canada Revenue Agency. Their tone is firm and formal. They tell you there's an unpaid balance, and if you don't deal with it now, you could face legal action or arrest.

    Then the pressure sharpens. They may tell you to stay on the line, not speak to anyone else, and make payment immediately using gift cards or cryptocurrency. That combination of fear, speed, and strange payment methods is a classic sign of fraud.

    The bank fraud department scam

    This version sounds helpful, not threatening. The caller says they're from your bank's fraud team and that they're trying to protect you from suspicious activity. They may ask you to confirm a card number, online banking details, or a verification code that just arrived by text.

    That code is often the main target. If you read it out, you may be giving them the final piece they need to access your account. The call sounds like security help, but the “verification” is really the theft.

    Real security teams don't need you to read back your password or one-time code on an unsolicited call.

    The fake service provider or tech support call

    A small business version of this scam often targets the person who answers the phone or handles admin tasks. The caller claims to be from the internet provider, software support team, or internal IT partner. They say there's an outage, a login issue, or a service update that requires your credentials.

    This works because the request sounds operational. It feels like part of keeping the business running. But handing over a password during a call can open the door to email accounts, file access, and billing systems.

    The Government of Canada's Get Cyber Safe guidance says Canadian vishing reports often involve spoofed caller IDs that mimic banks or tax offices, threats like arrest or account trouble, and demands for prepaid gift cards or cryptocurrency, as outlined in this Get Cyber Safe article on vishing warning signs.

    Red flags worth memorising

    • Urgent threats: Arrest, account closure, or service suspension unless you act now

    • Odd payment methods: Gift cards, prepaid cards, wire transfers, or cryptocurrency

    • Pressure to stay on the line: The caller doesn't want you to think or verify

    • Requests for secrets: Passwords, PINs, or one-time verification codes

    • Trust based on caller ID: A familiar number or label is not proof

    If any of those appear, treat the call as hostile until proven otherwise.

    Vishing vs phishing vs smishing

    These three terms describe the same basic trick. A scammer pretends to be trustworthy and pushes you to act before you stop to verify. What changes is the channel they use to reach you.

    The simple comparison

    Scam type Main channel What it usually looks like
    Vishing Voice call Someone phones you and asks for information, account access, or payment
    Phishing Email A message urges you to click a link, sign in, or open an attachment
    Smishing SMS text A text message pressures you to tap a link or reply with personal details

    An infographic comparing Vishing, Phishing, and Smishing, illustrating how these social engineering attacks use different communication channels.

    A helpful way to separate them is to ask one question first. Did the scam reach you by phone, email, or text? That answer usually tells you whether you are dealing with vishing, phishing, or smishing.

    Why vishing often feels more believable

    A phone call puts you under social pressure in a way email and text often do not. You hear a calm voice, a confident script, and sometimes a threat that sounds official. For many Canadians, that can feel more real than a suspicious email sitting in an inbox.

    That matters in Canada because vishing often copies familiar institutions such as the CRA, a bank, a telecom provider, or a local police service. The scam is not smarter because it uses the phone. It is more persuasive because it feels like a live conversation, and live conversations make people want to respond, explain themselves, or be polite.

    Proofpoint explains in this overview of why vishing is especially dangerous that voice-based attacks work well because they rely heavily on urgency and trust. Small businesses can be exposed too, especially when a caller reaches a receptionist, office manager, or anyone who can reset passwords, approve payments, or share account details.

    If you want a clearer comparison with email-based fraud, our guide to what email phishing is and how to secure your inbox breaks down how those attacks work.

    Where PIPEDA fits in

    PIPEDA stands for the Personal Information Protection and Electronic Documents Act. It is Canada's federal private-sector privacy law, and the official text is available on the Government of Canada's PIPEDA page.

    For an individual, the plain-language takeaway is simple. Personal information shared during a scam call can expose your identity, finances, or accounts.

    For a small business, the stakes are wider. If an employee gives a scammer customer records, payroll details, or login credentials over the phone, the problem may go beyond fraud. It can also become a privacy incident with legal and reputational consequences.

    Email, text, and voice scams all aim for the same result. They want trust before verification.

    How to protect yourself

    The good news is that your defence doesn't need to be technical. It needs to be consistent.

    An infographic titled How to Protect Yourself from Vishing with eight numbered tips for preventing phone scams.

    The safest routine to follow

    Trend Micro recommends in this practical guide to avoiding vishing that you verify the caller's identity through official channels, never use a number the caller gives you, hang up on unsolicited calls asking for personal information, and use two-factor authentication.

    That advice works because it breaks the scam at the exact point where it depends on momentum. The caller needs you to stay in their version of reality. Hanging up ends that advantage.

    What to do when the phone rings

    • Pause first: If the call is unexpected, don't assume it's legitimate just because it sounds professional.

    • Refuse sensitive requests: Don't share passwords, PINs, banking details, or verification codes.

    • End the call: You don't owe a suspicious caller politeness or extra time.

    • Look up the official number yourself: Use the organization's official website, app, or card.

    • Call back independently: If there's a genuine issue, the organization can confirm it through a verified number.

    A plain-language script you can use

    You don't need a perfect response. A short script works well:

    “I don't verify personal information on incoming calls. I'll contact the organization directly.”

    That one sentence does a lot. It stops the social pressure, avoids argument, and gives you a safe next step.

    If you want more help spotting fraudulent messages before they turn into calls, our guide on how to identify phishing emails covers the warning signs in plain language.

    Small habits that make a big difference

    A few habits lower your risk a lot:

    • Use two-factor authentication: If a password is stolen, 2FA adds another barrier.

    • Be careful with caller ID: It can be spoofed, so treat it as a clue, not proof.

    • Watch for payment pressure: No legitimate caller should demand gift cards or crypto.

    • Slow the moment down: Urgency is part of the attack. Taking a minute helps you think clearly.

    Awareness isn't about becoming paranoid. It's about making verification your normal habit.

    How Businesses Can Defend Against Vishing

    For a business, vishing is more than an annoying phone scam. One convincing call can lead to stolen credentials, unauthorised payments, or exposure of personal information covered by PIPEDA.

    Training people to recognise the pattern

    Many small business owners focus heavily on email security and forget the phone channel. That's understandable. Email threats are visible in your inbox, while vishing hits whoever answers the call at the wrong moment.

    Training needs to reflect that reality. Staff should know that a caller who sounds informed or authoritative can still be a fraudster. They should also know that no one gets in trouble for slowing down and verifying.

    A good awareness programme should include examples that feel familiar. A fake bank fraud call to finance. A fake internet provider call to reception. A fake executive request for urgent payment. We've written more about that broader approach in our guide to information security awareness training.

    Building verification into daily operations

    Policies matter because they remove guesswork. If your team has a rule that payment changes, credential resets, and sensitive data requests must be verified through a second channel, the scam gets harder to complete.

    Here are three controls that work well in practice:

    • Payment verification: Require a second approval path for new payment instructions or urgent transfer requests.

    • Credential protection: Ban password sharing over phone calls, even when the caller claims to be from IT or a vendor.

    • Callback procedures: Staff should end unexpected calls and use a verified contact list to call back.

    Choosing secure communication habits

    Vishing often succeeds because attackers collect context before they call. Public staff pages, exposed contact details, and weak internal processes can all make impersonation easier. That doesn't mean businesses should hide everything. It means they should be deliberate.

    Secure email is part of that wider culture. So are spam filtering, phishing detection, clear admin roles, and limiting who can approve sensitive actions. We think privacy-focused infrastructure also matters because it reduces unnecessary exposure and keeps communications under clearer control.

    One honest trade-off is that no tool can stop every social engineering attempt by itself. You still need trained people and simple processes. The strongest defence is a combination of awareness, verification, and secure systems that support both.


    If you want a private email service that supports a stronger security culture, take a look at Typewire. We're a Canadian private email provider based in Vancouver, and we run our own infrastructure rather than relying on third-party cloud platforms. That means email stays hosted in Canada under Canadian privacy law, with no ads, no data mining, and a straightforward focus on secure email for individuals and small businesses.

  • What Is a Phishing Link? How to Check a Link Before You Click

    What Is a Phishing Link? How to Check a Link Before You Click

    A phishing link is a deceptive link in an email, text, or message that looks legitimate but sends you to a fake website. Its goal is to trick you into handing over sensitive information such as passwords, banking details, or credit card numbers.

    You've probably seen one before. It might look like a note from your bank, a courier update, a password reset, or a message saying your account will be locked unless you act right away. The design may look polished, the logo may seem right, and the wording may sound urgent enough to make you click before you think.

    That's what makes phishing effective. It doesn't usually break into your account by force. It tries to get invited in.

    Last updated: 2026-07-13

    What Is a Phishing Link?

    A phishing link is a malicious web link disguised as something safe. You might get it in an email, text message, social media message, or chat app. It often claims to come from a trusted organisation, but the actual destination is controlled by a scammer.

    Imagine a fake storefront. From the street, it looks like your bank, your email provider, or a familiar shop. Once you step inside, the people running it try to take your wallet, copy your keys, or follow you home.

    That's why phishing is more than spam. Spam is often just unwanted noise. Phishing is fraud that uses trust as the bait.

    An infographic explaining what a phishing link is, detailing suspicious emails, impersonation, malicious URLs, and data theft risks.

    What the link is trying to do

    Most phishing links aim to push you into one of a few actions. They want you to sign in on a fake page, enter payment details, download malware, or approve access to your account.

    The danger usually starts with a believable story. A message says there's suspicious activity on your account, a missed delivery, or an invoice waiting. The link looks like the fastest way to fix the problem.

    Practical rule: If a message creates urgency and asks you to click, slow down before you do anything else.

    Nearly all phishing emails and internet scams involve a malicious URL, and link manipulation is a common trick where the visible text says one thing while the actual destination goes somewhere else, as KnowBe4 explains in its guide to phishing and link manipulation.

    Why this matters in Canada

    This isn't just bad online behaviour. The Canadian Anti-Fraud Centre states that phishing may constitute fraud under Section 380(1) of the Criminal Code, with a maximum penalty of 14 years' imprisonment, as outlined in its official page on phishing and related fraud offences.

    For everyday users, the more immediate issue is privacy and account security. If a fake site collects your login, that can expose email, financial records, saved contacts, and business information. Under PIPEDA, organisations handling personal information in Canada have obligations around protection and safeguards, which is one reason phishing remains a serious operational risk for businesses as well as individuals.

    How Phishing Links Work

    A phishing link works like a fake street sign. It points you toward a place that sounds familiar, but the road leads somewhere else.

    The scam usually has two parts working together. First, the message creates a reason to act. Then the link sends you to a page that copies a real service closely enough to catch people who are in a hurry. That page may ask for your password, payment details, a security code, or even permission to download a file.

    An infographic explaining how to identify malicious phishing URLs by analyzing their structure and domain components.

    Read the link from right to left

    When you inspect a link, start with the main domain near the far right. That tells you who controls the site.

    Take a link like this:

    secure-bank.example.com.malicioussite.net/login

    It is easy to notice "secure-bank" first and stop reading. The site owner is malicioussite.net. Everything before that can be arranged to look convincing, like a fake storefront sign placed in front of the wrong building.

    A few common tricks appear again and again:

    • Typos that look close enough like paypaI.com or a misspelt brand name

    • Subdomain tricks like yourbank.security-check.example.net

    • Shortened links that hide the final destination

    • Brand names in the path rather than the domain itself

    HTTPS doesn't prove the site is legitimate

    The padlock can mislead people. HTTPS only means the connection between your device and the site is encrypted.

    A fraud site can still use HTTPS. A sealed envelope comparison helps here. The envelope may protect the contents during delivery, but it does not confirm the sender is honest.

    HTTPS protects the connection. It does not verify the identity behind the page.

    What can happen after you click

    Sometimes the goal is obvious. A fake sign-in page asks for your email and password. Sometimes it is quieter than that. The page may try to load malicious code, trigger a file download, or collect technical details such as your IP address, browser, and device type for later targeting.

    If you click a phishing link but do not enter anything, that is still a warning sign, not always a disaster. In many cases, closing the page quickly limits the harm. You should still change your password if you were already signed in somewhere sensitive, run a device scan, and watch for follow-up emails or texts that build on that click. For Canadians, this matters at both a personal and business level. If a compromised account leads to exposure of personal information, PIPEDA can come into play for organisations that collect, use, or disclose that data. The scam itself can also connect back to fraud offences under the Criminal Code, as noted earlier.

    Phishing messages also hide clues outside the link itself. Sender names, reply-to addresses, tone, formatting, and unusual requests often give the scam away before you ever inspect the URL. Our guide on how to identify phishing emails with expert tips to stay safe explains those warning signs in plain language.

    How to Check a Link Safely

    The safest habit is simple. Don't click first. Inspect first.

    That pause matters because phishing often succeeds when people act on autopilot. If you build a routine for checking links, you turn a reflex into a security step.

    A close-up view of a person using a computer mouse to click on a phishing email link.

    Use hover to reveal the real destination

    On a desktop or laptop, place your mouse over the link without clicking. Most email apps and browsers will show the link's destination in a preview area.

    On a mobile device, you often need to press and hold the link to preview it. Don't tap quickly. A quick tap may open the page before you've checked anything.

    Look for signs like these:

    • Mismatched domains where the message says one company but the preview shows another

    • Odd strings of text with random letters, extra words, or long tracking fragments

    • Unfamiliar endings that don't match the service you expected

    • Brand names pushed left into a subdomain to distract you from the actual domain on the right

    Verify through a separate path

    If a message claims there's a problem with your bank, package, or email account, don't use the link in that message. Open a fresh browser tab and type the known website address yourself, or use the company's official app.

    This step feels slower, but it removes the attacker's shortcut. You're no longer trusting their route.

    A related clue lives in the message header. Headers show technical details about where a message came from and how it travelled through mail servers. They can look dense at first, but they're useful when a sender address seems off. Our article on how to read an email header and spot a fake sender breaks that process down.

    When a link preview still isn't enough

    Some links are shortened or heavily obfuscated. In those cases, it helps to get a second opinion before you visit the site.

    The short video below shows common patterns and reinforces the habit of checking before clicking.

    Quick habit: If you didn't ask for the message, don't trust the link inside it until you verify the destination another way.

    What to Do If You Clicked One

    If you clicked a phishing link, don't panic. Panic leads to rushed decisions, and rushed decisions can make a bad moment worse. What helps now is a calm, ordered response.

    The first question is simple. Did you only click, or did you also enter information? Those two situations overlap, but the next steps aren't exactly the same.

    An infographic detailing the immediate steps to take if you have accidentally clicked a phishing link.

    If you clicked but didn't enter anything

    Many people assume they're safe if they closed the page before typing a password. Sometimes that's true. Sometimes it isn't.

    The Canadian Centre for Cyber Security notes that phishing clicks can result in malware infection or session hijacking even when users don't submit credentials. The click itself can expose your device to infection, which is why avoiding suspicious links is as important as avoiding credential theft.

    Here's the immediate checklist:

    1. Disconnect from the internet if the page triggered a download, opened strange pop-ups, or redirected several times.

    2. Run a full malware scan with your trusted security software.

    3. Close your browser and reopen it. If you were signed into sensitive services, sign out and sign back in.

    4. Review active sessions for important accounts like email, banking, and work tools. If the service lets you sign out other sessions, use that option.

    5. Report the message to your email provider, workplace IT team, or the Canadian Anti-Fraud Centre if it appears to be part of a scam attempt.

    If you clicked and entered credentials or payment details

    Move faster here, but stay methodical.

    • Change the affected password immediately from the legitimate site, not the link you clicked.

    • Change any reused passwords on other accounts. Reuse is what turns one mistake into several account takeovers.

    • Turn on two-factor authentication if the service offers it.

    • Contact your bank or card provider if you entered payment information.

    • Watch for follow-up messages. Attackers often return after one successful interaction.

    If your password manager normally autofills on a real site and suddenly doesn't, treat that as a warning sign.

    If this happened on a work device, tell your IT or security team right away. If it happened on your personal email, report it through your provider's phishing report option and monitor the account closely for changes you didn't make.

    Tools to Scan Suspicious Links

    Manual checking should be your first move. A scanning tool is your second opinion when the link is shortened, hidden, or still looks suspicious after inspection.

    Here's a simple comparison of well-known options:

    Tool Best use What it helps with
    VirusTotal Unknown or suspicious URLs Checks a link against multiple security engines
    Google Safe Browsing Quick reputation check Flags many known dangerous websites
    URL expander tools Shortened links Reveals the full destination before you visit

    These services don't guarantee a link is harmless. New phishing sites can appear before scanners catch them. Still, they're useful when a link preview doesn't tell you enough.

    A good rule is to use a scanner when the destination is hidden, when the message is unusually urgent, or when the sender wants you to log in immediately. If the scan result is unclear, don't “test” the link yourself.

    If you're choosing protection for a team, our guide to anti-phishing programs for business protection compares the kinds of tools organisations use alongside user training.

    Preventing Phishing Attacks with Secure Habits and Email

    A phishing message usually asks you to make one bad decision quickly. Good protection comes from making a few calm decisions the same way every time.

    That matters in Canada for more than personal safety. If a phishing email exposes customer, employee, or vendor information, a business can end up dealing with privacy obligations under PIPEDA, along with the cost of investigation, notification, and recovery. For the criminal on the other side, creating or distributing phishing links can also lead to fraud charges under the Criminal Code.

    A simple routine works well:

    • Pause when a message creates urgency. Late fee notices, account warnings, and delivery problems are common bait.

    • Go to the company yourself. Type the known web address into your browser or use your saved bookmark instead of the link in the message.

    • Treat login pages like your front door key. If you did not expect to sign in, do not enter your password there.

    • Report suspicious messages so your provider, workplace, or the Canadian Anti-Fraud Centre can track patterns and warn others.

    Habits that lower your risk

    Daily habits do a lot of the work:

    • Use unique passwords so one stolen password does not open several accounts

    • Turn on two-factor authentication for email, banking, and work tools

    • Keep devices updated so your browser and operating system can block known malicious behaviour

    • Use a password manager because it can recognise the correct domain and stay silent on a fake one

    That last point helps in a very practical way. A password manager works a bit like a key cut for one lock only. If the site is a copycat, the manager usually will not offer to fill your login details, which is a useful warning sign.

    Your email provider matters more than people think

    Many phishing attacks start in the inbox, so your email setup affects how many risky messages you ever have to deal with. Filtering, attachment scanning, domain checks, and spy pixel blocking all help reduce the number of traps that reach you.

    Business model matters too. A provider focused on paid email and privacy has a clearer reason to invest in inbox protection without treating your messages as a source of ad data. Typewire, for example, runs its own infrastructure in Canada and focuses on practical protections like phishing detection, virus filtering, encrypted email, and spy pixel blocking—designed specifically so your inbox is easier to trust. That does not remove the need for careful habits, but it can cut down the number of suspicious emails that make it to your screen in the first place.

    Reporting matters too

    Online fraud is common enough that even careful people will run into phishing attempts. As noted earlier, phishing and spam operate at a very large scale. That is why reporting matters, even if you spotted the trick in time and did not lose money.

    If you click a phishing link but do not enter any information, do not assume nothing happened. Sometimes the click only opens a fake page. Sometimes it also confirms to the sender that your address is active, or tries to trigger a malicious download. Close the page, disconnect if something starts downloading, run a security scan, clear your browser if needed, and change your password if you entered it or if the site looked close enough to create doubt. If the account is important, review recent sign-in activity too.

    If you are in Canada, reporting the message to the Canadian Anti-Fraud Centre can help investigators connect separate complaints into a clearer pattern. Reporting it to your email provider or workplace also helps improve filtering for other people.

    Treat phishing like a stranger asking you to hand over your house key through a cracked door. You do not need to argue with them or prove they are suspicious. You close the door, check who they are through a trusted channel, and report the attempt if needed.

    If you want a private email service built for security, filtering, and Canadian data residency under PIPEDA, take a look at Typewire. We run our own infrastructure in Canada, avoid ads and data mining, and focus on practical protections like phishing detection, virus filtering, encrypted email, and spy pixel blocking so your inbox stays easier to trust.