Static snapshot. A frozen copy of the operator dashboard, safe to open anywhere. The buttons below are drawn but inert — recording a verification and being refused the release is a state change, so it runs on the live app: python src/demo.py --serve.
- From
- finance@rnetrotraders.com
- Received
- 29 Jun 2026, 00:25
- Subject
- INV-4453
- Reply to
- not a reply
- Thread
- THR00729
Lookalike domainFirst email ever from this sender
The message
Hi there,
Our treasury has consolidated everything into a single facility this quarter, and settlements now arrive at 374626070442 (SBIN0332609).
That covers INV-4453, which remains unsettled, as well as the monthly billing that continues.
Our GST registration is 07RPSFE4876T1Z4.
Value is Rs 17,168 inclusive.
Thanks,
Kabir Shah
Metro Traders
What the mailbox history shows
result
check
finding
Concern
First email ever from this sender inbox_first_contact
no earlier message from this sender is in the mailbox — a first contact asking about a payment destination
from Mailbox history
Everything here is Tier 2. A mailbox owner can send themselves messages and build a thread to any depth, so this evidence may hold a payment and can never release one.
What the sender resolved to
- Supplier
- VEND0048
- Matched on
- Lookalike domain
- Because
- built to be mistaken for this supplier's real domain
- Domain matched
- metrotraders.com
- Triage decision
- Needs review
- Change request filed
- doc_0bc99c60713dc508
mentions an account, a bank or a settlement destination
Sender matching decides whether a message is read in full. It never decides a payment on its own — a lookalike domain is a reason to look, not a reason to reject.
What happens to the payment
Released
Routine payment — nothing was being changedR2a_no_change_confirmed