Email Scam Checker Email Scam Checker
Feature

BEC Detection: First-Time Senders and Impersonation

A caution on email from a domain you have never received mail from before - and a lighter score for the senders you actually know.

BEC Detection: First-Time Senders and Impersonation
P

Pavel Demidovich

Developer and Founder of Email Scam Checker

In short

Business email compromise does not look like a scam. It looks like a short, polite message from somebody with a reason to write to you - a supplier with a new account number, an executive asking whether you are free, a colleague forwarding an invoice that needs paying today. There is no bad grammar and no wild threat, because the attacker is not trying to alarm you; they are trying to be unremarkable.

The signal this feature is built on is not the wording. It is sender history: whether you have ever received mail from that domain before. An email from a domain with no history gets a first-time-sender caution; a domain you correspond with regularly earns a small credit instead. Two sides of one idea - the score moves with how familiar the sender really is.

  • The first email you receive from a domain is flagged as a caution worth 10 points.
  • A domain you have heard from several times lowers the score a little, so ordinary correspondence is not over-flagged.
  • Free mail providers are excluded from the caution, and a shared bulk-mail platform can never become a trusted contact, so the signal stays about real companies rather than the internet at large.

Why BEC looks harmless

Mass phishing has a signature. It is sent to thousands of people at once, so it cannot afford to be specific: the greeting is generic, the story is overblown, the link is suspicious, and the pressure is obvious. The 28 heuristic checks are built to catch exactly those things, and on that kind of mail they work - too well for anyone hoping to reuse the same template against one company.

BEC starts from the other end. The attacker picks a small number of targets and writes nothing a rule would recognise. The message uses your name, or your role. It refers to a real invoice, a real project, or to nothing at all - "Are you available?" is a probe that costs one line and reveals whether you will answer. It asks for something ordinary: approve this payment, update these bank details, send the file across, confirm the amount. There is often no link to hover over and no attachment to open, and no rewritten brand name for a check to spot.

Nothing in the wording stands out, because the wording is doing its job. The one thing an attacker cannot fake is a relationship. A domain appearing in your inbox for the first time today has never been part of your correspondence, and that gap is what this feature looks at. It is a different question from the ones the message checks ask - which is why it catches mail that passes all of them. For those checks, see heuristic scanning.

The first-time-sender signal

When you open an email, the extension asks one question about the sender's domain: have I seen this before? The answer comes from your own scan history, and it is looked up by domain rather than by address.

Matching by domain is deliberate. A real company rotates its From-addresses - billing@ one week, noreply@ the next, updates@ after that - and all of them are the same correspondent; a check that matched the whole address would treat every change of mailbox as a stranger. Subdomains are collapsed for the same reason, so mail from a notification subdomain counts as mail from the company behind it. And the check does not run at all for free mail providers: Gmail, Yahoo, Outlook, Proton Mail and their peers are shared by millions of unrelated people, so a first message from a random personal account says nothing. That exemption covers free mailboxes, and stops there. A bulk-sending platform's own domain is still a domain, so the first email you receive from one picks up the same caution as any other new sender - the platform exemption applies to trust, not to this flag.

When the domain really is new to you, the email picks up a middle-severity caution worth 10 points, and the note reads: "This is the first email you've received from the domain" - then names the domain - and finishes by advising extra care with requests for payments, logins, or sensitive information. Ten points is deliberately not decisive. On its own it leaves a clean email at Safe, with the note waiting in the detail list behind the badge; the moment a second signal appears beside it, the same email tips to Suspicious. The caution is a modifier, not a verdict.

One detail worth knowing about the mechanics: this check is one of the few that reaches the network, because the history it consults is not on the page in front of you. The lookup puts a single question to your own history, and the message body is not part of it - nothing about the wording of the email is sent anywhere. What it queries is a short record of the emails the extension has scanned for you, held in a private store tied to your installation and not visible to anyone else. If the lookup fails - you are offline, or the request errors - neither signal fires: no caution is added on a guess, and no trust is granted on a guess. Your scan finishes normally either way.

The trusted-contact signal

The other half of the same idea. Once the extension has scanned three or more distinct emails from a domain, that domain counts as a trusted contact, and mail from it earns a middle-weight positive signal that lowers the risk score by 10 points.

The purpose is false positives. A genuine but low-volume sender - a small vendor, a freelancer, a niche service you actually use - can trip a wording or formatting check by accident. If you clearly have a running correspondence with that domain, the score is softened a little to reflect it. That is not a clearance: 10 points off will not rescue an email carrying a high or critical finding, and a trusted domain that suddenly sends a mismatched reply-to or a suspicious link is still flagged. Trust here is a tie-breaker, not a shield.

Trust cannot be earned cheaply either. Free mail providers are excluded, so nobody collects credit by writing from a throwaway personal account, and the bulk-mail platforms are excluded too, since a domain shared by thousands of unrelated senders can never be evidence about any one of them. What remains is a company's own domain - the only kind of sender whose appearance in your inbox means something.

What it catches

The pattern this check is built for is a message asking for money or access, arriving from a domain that has no business being new to you.

  • The spoofed invoice. A supplier you deal with regularly, writing from a domain you have never received mail from, with an invoice attached and refreshed bank details inside it.
  • The change of payment details. A short note from a "finance" mailbox introducing itself and asking you to route future payments to a new account.
  • The availability probe. "Are you available?" or "Are you at your desk?" - the opening line of a conversation that ends in a favour, sent from a domain that has never written to you before.
  • The apparent colleague. A message signed with a familiar name but sent from a domain you have no history with, asking for something small enough not to seem worth verifying.

In each of those cases the check is not diagnosing the message. It is stating something about the sender: you two have no history. Given how much of BEC depends on a relationship that does not exist, that is worth knowing before you act on the request.

What it does not do

The name of the attack suggests more than this signal can carry, so the limits are worth stating plainly.

  • It does not verify that the sender is who they claim to be. A new domain proves nothing by itself - a legitimate first contact looks exactly the same.
  • It does not compare the display name against the domain. A message signed with a colleague's name from an unrelated domain is caught by a different check, one of the heuristics that reads the message itself.
  • It never blocks or delays the scan. The lookup happens after the verdict renders, and if it is slow or fails, the email keeps the verdict it already had.
  • It cannot see history that does not exist. The record starts when the extension is installed, so the first email you open from a company you have known for years may be flagged as a first-time sender. After that scan the domain is known, and the caution does not appear again.

Where neither signal applies - a domain you have exchanged mail with for years, or nothing but a free mailbox - the email is scored on its content alone, which is where the rest of the checks do their work. For the targeted attacks this feature is built against, see spear phishing vs phishing.

Final verdict

Business email compromise is hard to catch because there is nothing in the message to catch: the wording is fine, the request is ordinary, and the only thing wrong is the relationship it pretends to have with you. That is the gap the first-time-sender check fills. A domain you have never heard from brings a caution; a domain you correspond with brings a small credit. Neither decides the verdict on its own, and neither has to - they move the score in the right direction on exactly the emails where a wrong guess is expensive.

Frequently asked questions

It is a scam where the attacker impersonates someone you would trust - a colleague, a supplier, an executive - and asks for a payment, a change of bank details, or a quick favour. The message is usually short, polite, and free of the obvious red flags mass phishing relies on.

By remembering which sender domains you have actually received mail from. An email from a domain with no history with you gets a first-time-sender caution, which is the shape many BEC and spoofed invoice emails have.

The reverse signal. Once you have received mail from a domain several times, the extension treats it as familiar and lowers its risk score slightly, so ordinary correspondence does not get over-flagged.

No. It is a caution worth 10 points - enough to keep a lone flag at Safe, but enough to tip the email to Suspicious the moment any other signal appears alongside it.

No. The history is kept per installation and is not visible to anyone else using the extension.

No. Addresses on shared free providers are excluded, because a first message from a random personal account is not a meaningful signal - those domains are used by millions of unrelated people.

By domain. A legitimate company rotates its From-addresses between billing, noreply and updates while the domain stays the same, and subdomains are collapsed onto the same sender.

Deep-dive guide

This page covers what the feature does and when it fires. For the longer walkthrough, read Spear Phishing vs. Phishing: What's the Difference? .

Other features