AI-powered · Built for Canadian real estate

The phishing email built to look like your next client

AI reads every message before you do — the links, the attachments, and who really sent it. Lockbox holds the dangerous ones and tells you exactly why, in plain language you can forward to your broker.

30 days free · No credit card · From $8/month

Thirty seconds, one real example

A buyer inquiry about a listing, a meeting link that isn't a meeting, and what the AI does about it.

A fake buyer inquiry about 412 Maple Ave, open in an inbox Watch the demo · 30 sec

You were trained to answer strangers quickly

That's the job. It's also exactly what makes agents worth targeting. These are the phishing attacks written specifically for the way you work.

Fake buyer inquiries

A motivated out-of-province buyer who can't view in person, and needs you to open a link or a document first. The AI checks where every link really goes before you can click it.

Someone using your name

Your signature copied, one letter changed in the domain, sent to your own client list. The damage is to a relationship you spent years building.

Documents that aren't real

E-signature requests and closing documents that lead to a login page built to harvest your email password. Lockbox opens the attachments and follows the links so you don't have to.

Three steps, then it's just quieter

No software to install, no mail to migrate, and no change to how you send and receive email.

  1. Connect your inbox

    Sign in with Gmail or Outlook. Takes about two minutes. Your email keeps working exactly as it does today.

  2. AI checks every message

    Links, attachments, sender history and domain age — all analysed before the message reaches you. When the answer isn't obvious, Lockbox escalates to a second, stronger AI reviewer instead of guessing.

  3. You get the story, not an alert

    Dangerous mail is held out of your inbox and you get a short note explaining what it was and why. Everything else arrives normally.

Two layers of AI, and one that knows when to ask

"AI-powered" usually means a black box that returns a score. Here is what actually happens to a message, because you should be able to tell a client how the decision was made.

1 · Deterministic checks

Before any AI runs, Lockbox verifies the things that have exact answers: sender authentication, how old the domain is, whether the links resolve where they claim, known malicious links and files, and what is actually inside the attachments.

2 · AI reads it like a person would

A language model reads the message the way a careful colleague would — the pretext, the urgency, the mismatch between who this claims to be and how they are writing. This model runs on our own hardware in Canada.

3 · A second opinion when it matters

If the first pass isn't confident, the message is escalated to a stronger AI reviewer rather than guessed at. Borderline mail gets more scrutiny, not less — and you see which reviewer decided.

Every verdict comes with its reasons in plain English. AI that can't explain itself is not much use to someone who has to justify a decision to a client.

Your mail is yours

A tool that reads your email has to be straight with you about what it does with it.

We keep the verdict, not your mail

Clean and suspicious mail is never written to disk — only its result. Quarantined mail keeps a short encrypted excerpt, and a full copy exists only when you ask us to investigate. You set how long results are kept, and can clear your history any time.

Disconnect in one click

Removing a mailbox revokes Lockbox's access with your email provider immediately. Nothing is held hostage.

You set the caution level

Relaxed, standard, or strict. Mark senders as trusted. Review and release anything that was held — nothing is deleted.

Priced per inbox, not per incident

30 days free, no credit card. Pay yearly and two months are on us. Cancel any time.

Solo

One inbox, protected.

$8CAD /mo
or $80/year — two months free
Start free trial
  • 1 mailbox
  • AI screening on every message
  • Automatic quarantine with plain-language reasons
  • Scan your past email
  • Weekly summary
  • 90 days of scan results

Office

A small team, all covered.

$15CAD /mo
or $150/year — two months free
Start free trial
  • Up to 5 mailboxes
  • Everything in Team
  • Shared blocklist and trusted senders
  • One place to see every inbox
  • 1 year of scan results, with CSV export
  • Priority support

Brokerage

Every agent in the office, priced for volume.

Let's talk
Volume pricing for 6 mailboxes or more
Contact us for a quote
  • 6 mailboxes or more
  • Everything in Office
  • Volume discount — the more agents, the lower the per-agent price
  • Brokerage dashboard across all agents
  • Onboarding help for your team
  • Invoiced annually

All prices in Canadian dollars, plus applicable tax. A mailbox is one email address — connect your personal address, a team address and an assistant's on the same plan.

Questions agents ask

Does Lockbox work with Gmail and Outlook?

Yes. Lockbox connects to Gmail, Google Workspace, Outlook and Microsoft 365 accounts. You sign in with your existing provider — there's nothing to install, no mail to migrate, and no change to how you send and receive email.

Will Lockbox block emails from real clients?

Ordinary mail is left alone. Lockbox only holds messages it has specific reasons to distrust, and every held message stays in your account where you can review and release it. You can also set how cautious it should be, from relaxed to strict, and mark senders as trusted.

Does Lockbox store my emails?

Lockbox stores the verdict, not your mail. Clean and suspicious messages never have their body written to disk — only the result, the sender, the subject and the reasons. When a message is malicious enough to quarantine, a short encrypted excerpt is kept so you can see what tripped the scanner.

A full copy of a message is stored only when you click investigate or report a false positive — that request authorises us to retrieve it from your mailbox for analysis, and it is deleted when the investigation closes.

What kinds of phishing does Lockbox catch?

The attacks aimed at agents specifically: fake buyer inquiries carrying malicious links or attachments, meeting invitations that lead to credential-harvesting pages, messages impersonating you to your own clients, fraudulent e-signature requests, and lookalike domains built to resemble a brokerage or a lawyer's office.

How does the AI decide whether an email is dangerous?

Lockbox runs deterministic checks first — sender authentication, domain age, where each link actually resolves, reputation data and attachment contents. An AI language model then reads the message the way a careful colleague would, weighing the pretext and the urgency against who the sender claims to be. If that first pass is not confident, the message is escalated to a second, stronger AI reviewer rather than guessed at. Every verdict is shown with its reasons in plain language.

How long does setup take?

About two minutes. Connect your mailbox, choose how cautious Lockbox should be, and it starts screening new mail immediately. You can also run a one-time sweep of your past email to see what's already sitting in your inbox.

See what's already in your inbox

Connect a mailbox and let the AI sweep your past email for phishing you never noticed. Most agents find something in the first ten minutes.

Start your free trial