What Is Read-Time Fraud Detection?

Your other security already had its chance. Read-Time Fraud Detection is there for what happens next.

Every company that loses money to email fraud already had security. Spam filters, gateways, antivirus, authentication, the same names everyone runs. Those tools work before a message lands and stop enormous amounts of junk and malware you never have to see. But delivery security and decision security are two different things. The security you already have decides whether an email should reach you. It can't decide whether you should trust what that email is asking you to do.

That second decision is where the wire gets lost, and until now the person making it was on their own. Email Fraud Alert built the security that stands there with them. We named this category and we defined it. We pioneered Read-Time Fraud Detection (RTFD) in 2026, the only security that works at the moment of the decision itself, on the message in front of you, the instant you open it.

The security gap is at the keyboard

When a wire fraud succeeds, it isn't because the victim had no security. It's because the attack was built to clear all of it. It comes from a real account, carries no virus and no dangerous attachment, and asks for something ordinary. A wire. New payment instructions. A quick sign-in. There's nothing for a filter to strip or quarantine, so it clears every check and lands looking exactly like legitimate business. Every other layer does its job and waves it through.

Then an employee is at the keyboard, alone, deciding whether to click the link, scan the code, or change the wiring instructions. A working computer can still send money to a criminal. An authenticated email can still come from a hijacked account. The attacker isn't trying to break the lock on the door. They're trying to convince the person holding the key. That's decision security, and it's the one place email fraud actually succeeds, because it's the one place nothing was watching. Now something is. EFA reads the message with the person making the call, at the exact moment they make it.

What EFA Looks For

EFA checks for dozens of fraud signals every time you open an email — across the sender, domain, message, links, routing, authentication, payment language, QR codes, and the relationships between them. Some warning signs are obvious. Others are buried in technical details most people would never see.

  • Impersonation and lookalikes: Suspicious senders, domains, display names, and addresses designed to resemble people and organizations you trust.
  • Links and hidden destinations: Where links actually lead, including misleading domains, redirects, and destinations hidden behind familiar text.
  • QR codes and sign-in traps: Suspicious QR destinations, device-code requests, credential lures, and other attempts to move you into a fraudulent sign-in.
  • Email identity and routing: Unusual Reply-To addresses, third-party routing, authentication problems, and other signs that an email may not be coming from who it appears to be.
  • Payment and business fraud: Changed payment instructions, wire-transfer language, invoice and vendor impersonation, secrecy, urgency, and other signs of payment fraud.
  • Message manipulation: Hidden characters, disguised letters, suspicious formatting, and other techniques used to make fraudulent content appear legitimate.
  • Context that doesn't add up: New or unusual senders, suspicious domains, unexpected requests, and combinations of signals that become more meaningful together.

And those are only examples. EFA combines dozens of checks to determine what deserves your attention, then surfaces a plain-English warning on the email itself — before you click, reply, pay, sign in, or act.

What a warning means, and doesn't

A signal is a clue, not a verdict. A real invoice mentions money, a real bank sends links, a real coworker can be in a hurry, so one signal doesn't make an email a scam. What matters is when the sender, the wording, and the destination line up into something worth a second look. No tool catches every attempt, and anyone who says otherwise is selling the wrong thing. EFA shows you what it found and why, the decision stays yours, and the lookalike you almost missed today is the one you catch on your own tomorrow.

Why it matters

In its 2025 Internet Crime Report, the FBI's Internet Crime Complaint Center tied more than $3 billion in reported losses to business email compromise, and almost all of that money moved by wire or ACH. No malware. No compromised device. Ordinary-looking email that got read and believed.

Those losses aren't proof that cybersecurity doesn't work. They're proof that cybersecurity before delivery isn't the end of the problem. The email got through, someone trusted it, someone acted, and the money moved. That's the step we built EFA to cover: the moment you read the email and decide what to trust.

“I had received five emails from who I thought was Chase.”

— Gloria Moss, via Fox 5 Atlanta