Pumpkin
    Phishing Protection

    Phishing Protection Built for February Inboxes

    A fake IRS notice, a W-2 request from a partner who never sent it, documents attached from a client who doesn't have that email address. Email security for firms whose inboxes get hunted every filing season.

    More Than One Thing Has to Fail

    Filtering at the gateway, authentication on your domain, a second check at the moment of the click. Every single layer misses things. The point is that one miss doesn't end the day.

    Filtering That Reads Context

    Mail gets checked for forged senders, hostile links, and attachments that misbehave when opened. Most of what it catches never reaches anyone's inbox.

    Domain Authentication

    SPF, DKIM, and DMARC configured and set to enforce, so nobody can send mail that genuinely comes from your domain.

    Links Checked at Click Time

    A link that's clean on delivery can turn hostile an hour later. URLs get rewritten and checked again the moment somebody clicks.

    Email Security Dashboard

    Blocked mail, quarantined mail, and what each one was trying to do, in one place. The number worth reading isn't the total blocked. It's the handful that made it as far as quarantine, and who they were pretending to be.

    • Filing-Season Threat Feeds

      Fake IRS notices, W-2 requests from the managing partner who didn't send them, the client attachment that lands in February. Those campaigns are seasonal, so we tune for them.

    • Attachment Detonation

      Attachments get opened in a sandbox first, so the file that only misbehaves when opened does it somewhere that doesn't matter.

    • Impersonation Detection

      Display-name tricks and lookalike domains get flagged before anyone has to notice a single transposed letter at 6pm.

    • Quarantine You Can Review

      Suspicious mail is held, not deleted. Somebody can look, release what's real, and the filter adjusts from the correction.

    app.pumpkin.cloud/email-security/dashboard

    Email Threat Summary, This Week

    Live

    847

    Scanned

    23

    Blocked

    5

    Quarantined

    irs-refund@irs-gov.fake.com

    IRS Impersonation

    Blocked

    urgent@client-portal.phish.net

    Credential Theft

    Blocked

    w2-request@payroll-update.com

    W-2 Phishing

    Blocked

    Who It's For

    Any firm where a convincing email can move money or hand over a client's file

    CPA Firms

    IRS impersonation, W-2 requests, and 'here are my documents' attachments aimed straight at your preparers.

    Law Firms

    Wire instructions that change at the last minute, and client impersonation around closings and settlements.

    Financial Services

    Business email compromise, which is mostly patience and a convincing invoice rather than anything clever.

    Government Contractors

    Documented email controls for CMMC and NIST requirements, with reporting to back them up.

    app.pumpkin.cloud/email-security/domain-auth

    Domain Authentication Status

    SPF (Sender Policy Framework)

    Configured

    DKIM (DomainKeys Identified Mail)

    Active

    DMARC (Domain-based Auth)

    Enforcing

    Spoofed Emails Rejected (30 days)

    142

    Nobody Should Be Able to Send Mail as You

    With SPF, DKIM, and DMARC configured and set to enforce, mail forged from your exact domain gets rejected before it lands anywhere. That protects clients who'd otherwise receive a very convincing invoice from your address, and it protects your domain's reputation, which is slow work to rebuild once it's been used to send fraud.

    Here's the honest limit. Domain authentication does nothing about a lookalike domain registered yesterday with one letter changed. Those still arrive, they still look right at a glance, and they get caught by impersonation rules and by staff who've been trained to slow down. We do both, because either one on its own leaves the gap the other covers.

    Frequently Asked Questions

    Why do attackers keep aiming at accounting firms?

    Because you keep the good stuff in one place. Social Security numbers, bank details, a complete financial picture for hundreds of households. And in February everyone at the firm is tired and moving fast, which is precisely the condition phishing is built to exploit.

    How is this different from the spam filter we already have?

    Ordinary filters catch obvious junk. This adds sandboxed attachments, click-time link checking, impersonation analysis, and threat intelligence tuned to what actually hits tax firms during filing season. It won't catch everything, and we won't pretend otherwise, which is why we pair it with staff training.

    What is domain spoofing, and does this stop it?

    Spoofing is mail forged to look like it came from your own domain. SPF, DKIM, and DMARC set to enforce stop that outright. What they can't stop is a lookalike domain, one letter off from yours, registered last Tuesday. Those get caught by impersonation rules and by people who've been taught to look twice.

    Can staff get their quarantined mail back?

    Yes. Quarantine is reviewable, releasing takes a couple of clicks, and the system learns from what gets released. A filter nobody can override eventually gets switched off, usually during the worst week of the year.

    How fast does protection update for a new campaign?

    New detections propagate across the network as they're identified, typically within minutes of a campaign being spotted. That helps, and it isn't a guarantee. The first firm hit by a brand-new campaign doesn't get the benefit of anyone else's bad morning.

    Cut Down What Reaches the Inbox

    Get filtering, domain authentication, and reviewable quarantine running before the next filing season starts. Setup doesn't change how anyone on your staff works.