What you'll see
One message, one signal, never a pile of them
Impersonation is the attack Haven is built for, whether it wears a company's name or a colleague's. Haven shows exactly one thing per email, and a warning always outranks a reassurance, so a message can never be flagged and praised at the same time.
A brand you trust, or a person you know
The name says one thing and the message says another. A bank or payment service whose links lead off its own domains, or a colleague's name above an address from outside your company. Haven flags the gap and shows you where the link really goes.
“Link claims northpeak.example but goes to a different domain”A link inside doesn't hold up
No brand involved, just a link that failed on its own. The banner always names the reason, so you know whether it was a lookalike domain, a mismatched destination, or a redirect that lands somewhere unexpected.
“Haven detected suspicious links in this email”The language itself is the tell
Some phrases are so specific to scams that Haven warns on them even when every link is clean. Deliberately a very short list, because the cost of crying wolf on ordinary mail is high.
“This email uses high-pressure language commonly found in scam emails”We can tell you who sent it
A small chip beside the sender when the sending domain really does belong to the brand it claims. It names the domain rather than passing judgment, because knowing who sent something is not the same as knowing it's harmless.
“Verified, really northpeak.example”Proof it looked, even when nothing's wrong
Most mail is ordinary, and Haven still checks every link in it. A quiet chip says so, reporting the work rather than passing a verdict.
“Haven checked the links here”Every banner can be dismissed, and each one carries a thumbs up and thumbs down. If Haven gets a message wrong, one click tells us, and that feedback is what the detection improves on.
How it decides
Impersonation is a mismatch, not a word
Plenty of ordinary email mentions a brand. It counts as impersonation only when all three of these are true at once.
01
A brand is named
The body invokes a known brand. A name that appears only as link text pointing at that brand's real site is discounted, because that is a signature.
02
The sender isn't it
The sending domain is checked against the ones that brand really sends from. A match ends it. A brand name in the display field with no matching domain counts against the message.
03
The links go elsewhere
Links are unwrapped past trackers and redirects, then checked against the brand's real domains. All of them leading somewhere else is the strongest signal Haven has.
Urgency sits underneath all three. Pressure language lowers Haven's tolerance for a questionable link, but never flags on its own. Plenty of real mail is genuinely urgent.
Worth saying plainly
Verified means we know who, not that it's safe
“Verified, really northpeak.example”The chip states an identity: this really did come from the domain it claims. It will never say a message is safe, because a real company can send you something you shouldn't act on and we'd have no way to know.
Two things Haven doesn't do. It doesn't open or scan attachments, so an unflagged one is unexamined, not cleared. And it never deletes, moves, or blocks anything. It adds a banner and leaves the rest alone.
Where it works
In the inbox you already use
Email Protection runs inside the Haven browser extension, on the mail you read in your browser. There is no mailbox to connect and no account access to grant.
Gmail
Personal Gmail and Google Workspace at mail.google.com, including threaded conversations, where each message is assessed separately.
Outlook
Outlook on the web at outlook.live.com, outlook.office.com, and outlook.office365.com, covering personal accounts and Microsoft 365.
Answers to Your Questions
Get answers to commonly asked questions about Haven's email protection.
Contact us