CASE STUDY
Is This Legit?
Real-time email safety — built into Outlook
Matthijssen Business Systems | 2026
Phishing emails look more convincing every year. Attackers impersonate executives, banks, vendors, and even your own colleagues — and the emails often pass right through spam filters because they come from legitimate-looking infrastructure.
The result: employees are left to make judgment calls with no guidance, and a single wrong click can lead to a data breach, wire fraud, or payroll theft.
|
Common attacks we see:
|
What we kept hearing: “Is this a real email?” “I wasn’t sure, so I just ignored it.” “It looked legit to me.” “Why didn’t the spam filter catch it?” |
We built Is This Legit? — a Microsoft Outlook add-in that gives every employee an instant, plain-English safety analysis of any email, right inside Outlook. No extra apps. No training required. Just open an email and see the result.
|
34 safety checks |
0 local installs |
1–3s analysis time |
0 data collected |
When you open an email, the add-in automatically runs in the background. It checks 34 different signals — the sender's domain age, authentication records, display name vs. email address, body language patterns, attachments, and more — and gives you a result in seconds.
|
1 |
Open any email in Outlook — the add-in loads automatically |
|
2 |
A safety score (0–100%) appears with a color-coded verdict |
|
3 |
An ALERT line gives you the plain-English reason for any concerns |
|
4 |
Detailed check results are listed below, red flags first |
|
5 |
Three clear action steps tell you exactly what to do next |
|
90–100% |
✅ Looks Legitimate |
Passes all checks — no action needed |
|
75–89% |
🟡 Mostly Safe |
Minor concern — use your judgment |
|
55–74% |
⚠️ Proceed with Caution |
Review before responding or clicking links |
|
35–54% |
⛔ Suspicious Email |
Verify the sender by phone before acting |
|
0–34% |
🚨 Likely Phishing |
Do not engage — report as phishing |
Every example below is based on a real attack pattern encountered in production. Details have been anonymized.
|
📧 Payroll Diversion Attempt An employee received an email appearing to be from a colleague, asking to update their direct deposit information before the next payroll cycle. The display name matched the colleague's name — but the email came from an unrelated domain with a generic username. The add-in flagged it: name doesn't match username, financial request detected, and showed the combined alert PAYROLL DIVERSION RISK. The employee called HR to verify — the colleague had never sent it. Fraud prevented. |
|
📧 Company Impersonation (BEC) An email arrived claiming to be from a well-known company, requesting a callback for an 'urgent service requirement.' The display name looked legitimate. But the sender domain was completely unrelated, the body directed replies to a third domain, and the email contained 10 BEC language patterns. Score: 5% — Likely Phishing. The add-in showed a PAYROLL DIVERSION RISK combined alert. No response was sent. |
|
📧 Mass Phishing Campaign (Slipped Past Spam Filter) An email arrived with a professional layout, a PDF attachment labeled 'Statement,' and a button reading 'Access Secure File.' The sending domain was foreign (.com.au), the username was randomly generated, and the greeting said 'System User' instead of the recipient's name. The spam filter passed it. The add-in caught it: foreign domain, random username, impersonal greeting, and a MASS PHISHING PATTERN alert. Score: approximately 1%. |
|
✅ Correctly Cleared — Legitimate CFO Email A nonprofit's CFO sent a routine reply about a laptop repair. An early version of the add-in flagged it — her title in the email signature triggered 'authority language,' and the IT technician's email in the quoted reply chain triggered a contact mismatch. We fixed this by teaching the add-in to strip signatures, reply headers, and CAUTION banners before analyzing content. The email now scores 100%. |
Most security tools are built for IT teams. Is This Legit? is built for the person in accounting, HR, or operations who gets a suspicious email and doesn't know what to do next.
|
Every result includes: |
The three action steps shown every time: 1. Were you expecting this email? Use your best judgment if the sender is familiar. 2. If you know them — call and confirm. Use a known number, not one from the email. 3. If you don't recognize them — delete it. Report using the Report button in Outlook. |
We know security tools need to be trustworthy. Here is exactly what the add-in does and does not do:
|
|
|
🔒 The only external request The sender's domain name (e.g. example.com) is looked up against a public registration database (equivalent to a WHOIS search). No email content, personal data, or identifying information ever leaves your machine. Results are cached locally for 24 hours so the same domain is never looked up twice in a day. |
The add-in is deployed through the Microsoft 365 Admin Center and requires no software installation on any employee device. It can be added or removed centrally at any time.
Is This Legit? is available as part of Matthijssen Business Systems. It works inside Microsoft Outlook and requires no software installation on any employee device — no training, no configuration required.
Contact us: mattnj.com | Matthijssen Business Systems
Disclaimer: Is This Legit? is an automated tool intended to serve as an extra set of eyes — a supplementary layer of analysis to assist users in evaluating email indicators. It does not guarantee that any email is safe or malicious, and false positives can and do occur. This tool should never be the sole basis for any decision. Users should always exercise independent judgment, follow their organization's security policies, and take extra precaution with any email that raises concern — regardless of what the tool indicates. Is This Legit? is not a substitute for professional cybersecurity advice, training, or a comprehensive security program. Matthijssen Business Systems makes no warranties, express or implied, regarding the accuracy, completeness, or fitness for a particular purpose of this tool. Use of this tool does not transfer liability for any security incident, data breach, financial loss, or other harm. When in doubt, contact your IT or security team before taking any action.