Phishing Protection. Catches what the others missed.
You have layered email authentication. You bought a spam filter. You ran the awareness training. A phishing email still gets through, looking like DocuSign or an internal HR notice. The layers above stop known threats. Phishing succeeds because the message is plausible enough to bypass SMTP filtering, the spam filter, and even the user. You need a layer that inspects what the link actually points at, at the moment the user clicks.
Click-time URL inspection No endpoint agents
Click-time URL inspection
Every link in inbound mail is rewritten so the destination is inspected at the moment a user clicks, not just at delivery. This catches the "looked clean at SMTP, became malicious thirty minutes later" attacks that fixed-time scanning lets through, and the user is blocked before reaching a weaponized destination.
Ransomware and malware blocking
Attachment scanning and URL inspection together stop the most common ransomware delivery patterns before payload detonation. Macro-bearing documents, weaponized PDFs, and second-stage downloaders all get caught at the gateway rather than at the endpoint, where remediation costs run an order of magnitude higher.
Spear-phishing, impersonation, and BEC defense
Targeted attacks that use real executive names, real vendor brands, and invoice attachments that are just slightly off get inspected against impersonation patterns rather than relying on signature-based malware detection. The wire-transfer fraud message that looks plausible to a finance team gets flagged before the click.
Display-name and look-alike domain detection
Catches the typosquats and Unicode look-alikes that slip past simple name-based whitelisting. The attacker who registers a Cyrillic-letter twin of your CEO's domain, the punycode lookalike of a vendor you actually pay, the display-name spoof that shows the right name with the wrong reply-to. All flagged at scan time.
Works with what you already run
Deploys in front of Microsoft 365, Exchange (on-premises or hybrid), or any other hosted email environment. Inserted as an MX-layer service. No agents on endpoints, no app to install, no migration project. Standing up the protection layer is a DNS change and a few mail-flow rules. (Not built for Google Workspace; see below.)
Plans and pricing
DuoCircle Phishing Protection is per-user, starting at $32/month for 10 users. Per-user rate steps down from $1.80 to $1.60 as team size grows. Up to 1,000 users on the public catalog; above that is custom.
Pricing FAQ
How much does DuoCircle Phishing Protection cost?
Phishing Protection is priced per user. $32/month for the first 10 users, then $1.80 per additional user with volume discounts down to $1.60/user at 501+ users. A 250-user team costs about $464/month; a 1,000-user team is $1,616/month. Anti-phishing, ATP, spam filtering, DMARC reporting all bundled, no add-on fees.
What counts as a user?
Real-human mailboxes only. Aliases like sales@ and info@ are free; shared or group mailboxes accessed by multiple people bill at 50% of the per-user rate. Multi-domain pricing is separate — contact sales for a quote.
Is there a free trial?
Yes. 60 days, no credit card required. Convert to a paid plan only after you add a payment method. The slider above shows the per-user math for any team size.
Do you offer annual billing discounts?
Yes, annual billing saves 15-20% versus monthly. Annual is set up via sales rather than self-serve checkout — contact us for the annual rate on your tier.
Who this is for
- IT teams running Microsoft 365 that want a stronger anti-phishing layer than the platform default, without paying enterprise-tier prices for it
- Organizations on Exchange or hybrid infrastructure that need protection layered in front of mail flow without re-architecting
- Mid-market organizations where a single successful phishing attack would be costly and where users are inevitably going to click suspicious things
- Compliance-driven environments (financial, healthcare, government) on M365 or Exchange where email-based attacks have regulatory consequences
- Help desks tired of triaging phishing-incident tickets one URL at a time after the click already happened
When to look elsewhere
You need full vendor-managed phishing remediation, where our team triages and responds to incidents on your behalf. That is available through DuoCircle professional services rather than as part of the standard product.
You need a full Security Awareness Training platform with phishing-simulation campaigns, behavioral analytics, and curriculum-based modules. That is a different product category.
You are on Google Workspace. Phishing Protection is not the right fit. Google's built-in anti-phishing is genuinely strong on Workspace, and we do not think we add enough on top of it to justify the spend. Stay with what Google offers built-in.
Your built-in M365 anti-phishing is sufficient for your risk profile. Layering Phishing Protection on top is a real value-add, not a strict requirement. We would rather you pay for what you actually need.
What you get when you call
An expert on the call, not an SDR working from a script. When you contact us about phishing protection, you talk to an expert who has actually deployed phishing defense at customer scale. We tell you which layers you need and which you do not, even when the honest answer is that your current stack is already covering the threat model.