Communication provenance
Make every customer communication verifiable.
Fromenance is a communication provenance platform for banks, credit unions, insurers, and utilities. Your customer asks "did you really send this?" and gets a definitive answer in seconds, from your domain, with no human on your side.
You register every outbound communication at send time. The customer forwards a suspicious message to verify@yourbank.com or pastes it at yourbank.com/verify. Fromenance matches it against the registry and replies in your voice: Verified, Not verified, or Known fraud.
Three steps, one answer
Step 1: Register at send time
Your application, ESP webhook, or a journal BCC tells Fromenance that a specific message went to a specific recipient. We store a verify code, a one way hash of the recipient address, and a content fingerprint. Never the address, never the body.
Step 2: The customer asks
They forward the message to verify@yourbank.com or paste it at yourbank.com/verify. No account, nothing to install, and the Fromenance name never appears. Screenshots work too.
Step 3: A definitive answer in seconds
Deterministic matching on the code, the recipient, and the fingerprint. The reply comes from your domain, in your branding, with the next step for that verdict. Every failed verification becomes threat intelligence.
Three verdicts, and the wording is locked
The verdict block in every reply is fixed text your fraud team cannot soften and your marketing team cannot inflate. It says what the institution can stand behind and nothing more.
- Verified
"Verified: this message matches a communication we registered and sent to you on September 24, 2026 at 10:42 AM UTC."
The verify code resolved to a registration whose recipient matches the person asking, or the recipient and content fingerprint match a registration inside the retention window.
- Not verified
"Not verified: no registered communication matches this message. That does not by itself mean it is fraudulent, but treat it with caution."
No registration matches on any rule. Unregistered legitimate mail lands here too, which is why the wording is "no record", never "fraudulent", until the tenant is in Authoritative Mode.
- Known fraud
"Known fraud: this message matches an impersonation attempt our fraud team has confirmed. Do not interact with it."
An extracted indicator is on the tenant's fraud list, or the content fingerprint matches a submission an analyst already marked as fraud.
Unregistered legitimate mail returns Not verified with the words "no record", never "fraudulent". Once your coverage is reviewed, Authoritative Mode changes that reply to "we did not send this".What Authoritative Mode requires.
Try it against the real API
This runs on a demo tenant on api.fromenance.com with a public site key. What you see is real latency and the real verdict path, with no model anywhere in it.
Northfield Bank (demo) verify page
Demo tenant: Northfield Bank (demo). Site key sk_pub_demo_northfield. Real API, real latency.
Registered message
This fraud alert was registered at send time to jane.doe@example.com. The footer carries the verify code twice on purpose.
Northfield Bank We noticed a card transaction Hi Jane, A purchase of $412.90 at ACME ELECTRONICS was made with your Northfield Bank Visa ending in 4471 on September 24 at 10:42 AM. If this was you, no action is needed. If you do not recognize this transaction, review it in the app or call the number on the back of your card. Review this transaction: https://www.northfieldbank.com/app/alerts/tx/98812?utm=email Thank you, Northfield Bank Fraud Team Not sure this email is from Northfield Bank? Forward it to verify@northfieldbank.com or enter code KX73-PQ9G at northfieldbank.com/verify. Reference: KX73-PQ9G Northfield Bank, Member FDIC. 100 Main Street, Northfield, VT 05663. Privacy: https://www.northfieldbank.com/privacyNorthfield Bank Urgent: your card has been temporarily restricted Hi Jane, A purchase of $412.90 at ACME ELECTRONICS was attempted with your Northfield Bank Visa ending in 4471 on September 24 at 10:42 AM and has been placed on hold. To avoid permanent suspension of your card, confirm your identity within 24 hours. Confirm your identity now: https://northfield-bank-secure.com/login?ref=8812 Thank you, Northfield Bank Fraud Team Not sure this email is from Northfield Bank? Forward it to verify@northfieldbank.com or enter code QF29-TH40 at northfieldbank.com/verify. Reference: QF29-TH40 Northfield Bank, Member FDIC. 100 Main Street, Northfield, VT 05663.
The reply never quotes the suspicious message or its links. It says only what the institution can stand behind: a registered communication matches, or no registered communication does.
What DMARC does not answer
SPF, DKIM, and DMARC are necessary and Fromenance depends on them. They answer a different question than the one your customer is asking.
DMARC authenticates a domain, not a message
A lure sent from northfield-bank-secure.com with your logo pasted in passes SPF, DKIM, and DMARC for the attacker's own domain. Nothing in that chain tells your customer whether you sent it.
Gateways and classifiers give a probability
An 87 percent phishing score is useful to a SOC and useless to a customer holding the phone. They need a yes or a no that your legal and compliance teams can stand behind.
Brand protection finds lookalikes on a lag
Takedown vendors discover impersonation infrastructure after it is live. The customer who received the lure is the earliest sensor there is, and nobody else is listening to them.
Every failed verification is a phishing sample delivered by its target
A Not verified or Known fraud submission carries the attacker's domains, URLs, phone numbers, and QR payloads, sent in by the person the attack was written for. Fromenance extracts them deterministically, stores them per tenant, and exports them as CSV or STIX 2.1 today. Campaign clustering, IOC enrichment, and cross institution early warning are the intelligence tier on the roadmap.
Built for the people who own impersonation
Banks
Fraud alerts, transaction alerts, wire notices.
Credit unions
Member alerts with a five person fraud team.
Insurance
Claims, policy, and billing communications.
Utilities
Outage, billing, and disconnection notices.
Run a 60 to 90 day pilot on one communication stream.
Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.