Fromenance for banks
Your customers ask "did my bank send this?" Give them an answer.
Fromenance is a communication provenance platform for regional banks: you register every fraud alert, transaction alert, and wire notice at send time, and a customer who forwards a suspicious one to verify@yourbank.com gets Verified, Not verified, or Known fraud in seconds. It is the layer above DMARC that the customer can actually see, and every lure they forward becomes an indicator for your fraud team.
What your customers are receiving
The impersonation scenarios banks fraud teams see every week, and what a Fromenance verdict does to each one.
The fake fraud alert
"We noticed a card transaction" from northfield-bank-secure.com with your logo and a link to a cloned login page. It passes DMARC for the attacker's domain. Forwarded to verify@, it resolves to Not verified, and the domain lands in your indicators within seconds.
The copied footer
Attackers copy your real verify footer to look legitimate. The code is bound to one registration and one recipient, so a copied code on a different message resolves to Not verified and raises a replay flag. The lure just delivered itself to your fraud team.
The wire recall lure
A commercial customer gets a "wire on hold, confirm details" message. Registered wire notices verify in seconds; unregistered ones return no record. In Authoritative Mode the reply says you did not send it.
The compromised vendor account
Mail from a real but compromised third party domain passes SPF and DKIM. It is not in your registry, so it cannot verify. Your customer gets a definitive answer and the sending address becomes an indicator.
The QR code statement
A PDF or image with a QR payload pointing at a lookalike. Screenshot upload on yourbank.com/verify goes through OCR into the same deterministic extractors; the QR payload is stored as an indicator.
The 'is this real' call
Every contact center call tagged "is this real" costs roughly $8 to $15 and the agent often cannot answer authoritatively. The verify@ reply answers in seconds, on your domain, with your fraud contact for anything that still looks wrong.
Register these streams first
Coverage is the whole game. Start with the communications customers already scrutinize, because those are the ones they will forward.
- 01
Fraud alerts
The stream customers scrutinize most and forward most. The best first stream for a pilot, and where footer replay is most likely to be observed.
- 02
Transaction and card alerts
High volume, template driven, easy to register from the ESP webhook. Customers already know what a real one looks like, so a lure stands out when it fails.
- 03
Wire and ACH notifications
Lower volume, highest value per message. Register through the API or the journal path from the core banking or treasury platform.
- 04
Statements and account notices
Batch runs from a statement vendor. Use the batch endpoint (up to 1,000 per call) or add journal-{slug}@ingest.fromenance.com as a BCC on the vendor's sending system.
Outcomes you can put in front of the board
Every metric below is captured by the product itself, so the pilot report is a dashboard export.
Call deflection
"Is this real" call volume on the pilot stream, before and during. You supply the contact center tags; the product supplies verification attempts split by forward and web.
Abuse mailbox triage
Volume before and during. Analyst time on suspicious message triage per week. Submissions arrive pre-extracted with indicators and a verdict, so triage becomes review.
Account takeover and reimbursement
ATO events traced to phishing of the pilot stream, card reissue, disputes, and reimbursement. Earlier Known fraud verdicts shorten the window in which a campaign works.
Campaigns discovered
Unique campaigns and time from first submission to analyst confirmation. Lookalike domains discovered. Intelligence yield: indicators your existing feeds did not have.
Trust in real mail
Every campaign teaches customers not to trust genuine mail, which drags on digital servicing adoption. A verifiable footer on every alert is a reason to keep reading them.
A defensible answer
"We sent this to you on September 24 at 10:42" or "no registered communication matches". Wording your legal and compliance teams reviewed once and that never changes in production.
Compliance framing
Fromenance is a customer facing fraud control with an audit trail: every verdict is immutable, every analyst action is logged, and every registered communication has a record of when it was sent and to whom (as a one way hash). That maps to what examiners ask for under FFIEC guidance on customer authentication and fraud response, and it gives your incident reports a timestamped source of truth. We do not claim regulatory certification; we give you the evidence.
The pilot, week by week
60 to 90 days on one stream, fixed fee credited to the first annual contract, with onboarding help and a written report.
Step 1: Week 0
Contract and DPA, tenant created, TXT record published, redirect rule live, forwarding test passed.
Step 2: Week 1
One stream registered, footer deployed to that template, reply identity live on your domain.
Step 3: Weeks 2 to 12
Run. Weekly 30 minute review of Submissions and Indicators with your fraud lead. Reports at day 30, 60, and 90.
Questions evaluators ask
- Do we have to route customer mail through Fromenance?
- Only the messages customers choose to forward to verify@yourbank.com, and only after the forwarding hop passes DKIM or ARC for your domain and your TXT record checks out. If your security review prefers to start smaller, the web verify page needs no mail routing at all.
- What does the customer see?
- A reply from verify@verify.yourbank.com (or a subdomain you choose) in your branding, with the locked verdict and a next step. The Fromenance name never appears. On the web page, the same template renders in place.
- How does this fit our existing DMARC, gateway, and brand protection?
- It sits above them. DMARC authenticates your domain, the gateway filters inbound mail to your staff, brand protection takes down lookalikes. None of them answer the customer holding the phone. Fromenance does, and it feeds indicators to all three.
- Which stream should a bank pilot first?
- Fraud alerts and transaction alerts. Customers already scrutinize them, they are template driven, and the ESP webhook or a single API call registers them without touching the core.
- What if our core banking vendor cannot call an API?
- Add journal-{slug}@ingest.fromenance.com as a BCC or journaling target on the vendor's sending system. We receive the full message, hash the recipient, fingerprint the body, and register it. Pair it with a static per template code or the reserve flow for the footer.
Run a 60 to 90 day pilot on one communication stream.
Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.