I've spent twenty-five years building systems for banks, insurers, and compliance teams. I thought I understood impersonation fraud.
Then my mother called the number.
What Happened
In July she got an email that looked exactly like every other email her bank had ever sent her. Same logo, same colors, same tone. Suspicious activity on your account. Secure it now. A link.
She did what careful people are told to do. She didn't reply. She didn't type a password into the email. She clicked through to see what was going on, and landed on a page that didn't look close to the bank. It looked like the bank. And it gave her a phone number to call.
She called it. A calm, professional voice answered with the bank's name, thanked her for acting so quickly, and walked her through "securing" her account. Of course they were expecting her. They wrote the email, built the page, and put their own number on it.
The email said her account had been hacked. It hadn't been. It was being hacked, right then, while she was on the phone with the people doing it. The urgency wasn't a warning about the crime. The urgency was the crime. By the time she hung up, relieved, thousands of dollars were gone.
She's fine. She's sharper about this now than almost anyone I know, and she gave me permission to tell it.
Every Control Worked
Here's the part that kept me up at night, and it's the part anyone in security should sit with for a minute.
Nothing failed. The bank had DMARC, and DMARC did its job: the email didn't come from the bank's domain, so DMARC had nothing to say about it. Her mail filter let it through because it looked like a thousand legitimate messages. The copycat site eventually got taken down, which helped the next person and did nothing for her.
Every control in the chain was working as designed. Not one of them could answer the only question she actually had:
Did my bank really send this?
And here's the worst of it. Even if she had found the real number and reached a real agent, the agent couldn't have answered it either. They'd have looked at the same email she was looking at, and guessed. The one party that knows for certain whether a message is real is the institution that did or didn't send it, and institutions send millions of messages without keeping any record a customer can check against.
So customers are left judging appearance. And appearance is exactly the thing the attacker controls.
Ground Truth, Not Probability
Most anti-phishing technology works on probability. Classifiers score how phishy a message looks. Brand-protection services hunt for lookalike domains. Those tools are valuable, and I'm not knocking them. But none of them are authoritative. They infer. They don't know.
Fromenance flips it around. The institution registers every communication as it goes out, with a short verification code inside it. When a customer wonders, they forward the message to an address on the bank's own domain, or type the code on the bank's own page, and within seconds they get one of three fixed answers:
- Verified. It matches a communication we registered.
- Not verified. No registered communication matches.
- Known fraud. It matches a confirmed impersonation campaign.
No score. No "probably." No wording that claims more than the record supports. The name is literally the question: From + Provenance. Where did this actually come from?
A copied code on its own doesn't pass, either. A code has to match the recipient it was registered for, so an attacker who lifts the verify footer out of a real email and pastes it into a lure gets flagged as a replay, not a match. The first thing a smart attacker does is copy the trust signal. The system has to assume that from day one.
If my mother had been able to forward that email to her bank and get "not verified" back in a few seconds, she would not have called that number. I'm as sure of that as I am of anything, because the reason she called was that she wanted someone to confirm what was going on. She was looking for exactly this. It didn't exist.
The Other Half
There's a second thing in that story I didn't appreciate until later. That email, the copycat page, and the phone number were a complete phishing kit, delivered straight into the hands of a real customer of the targeted bank. If she'd had a way to forward it, the bank's fraud team would have had the lure, the domain, and the number within seconds, while the campaign was still live.
Instead it sat in her inbox, and the number kept ringing for whoever called next.
So every message that fails verification in Fromenance goes to the institution's fraud team with the domains and phone numbers already extracted. The customers worried enough to ask become the fastest threat intelligence feed the bank has. Verification is the wedge. The intelligence is the second product. And the record of what was really sent, across institutions, is the moat.
How It's Built
Because I can't help myself, a few notes for the engineers:
- It runs on Cloudflare Workers end to end: API, admin app, operator backoffice, docs, marketing, and the embeddable verify widget, with D1 at the edge, R2 for raw submissions, Queues for ingest, matching, replies, and intel, and Neon Postgres as the system of record.
- Institutions prove domain ownership with a TXT trust record that's re-checked daily, and a domain that stops proving it gets suspended automatically.
- Every route that takes an ID has a tenant-isolation test asserting that bank B gets a 403 or 404 on bank A's objects. That suite found one real leak before launch. That's why you write it.
- The admin app signs in with Identizen, my accountless phone-based identity project, alongside magic links and passkeys. It seemed wrong to build a trust product on passwords.
Why I'm Telling You This
When I talk to security teams about impersonation, the conversation stays abstract. Takedown rates. DMARC coverage. Classifier precision. Those numbers matter. But the customer on the phone, being told her account is hacked by the people hacking it, is what the numbers are for.
Fromenance went live this week. It's built so the next person in my mother's position can ask one question and get a straight answer before they pick up the phone.
If you run fraud, security, or digital channels at a bank, credit union, insurer, or utility, and this story sounds familiar, I'd like to hear yours.
Fromenance is live at fromenance.com, with a working demo that returns real verdicts. My mother's story, in the long form, is on the Fromenance blog. If you'd rather talk it through, book a call.