Static snapshot. A frozen copy of the operator dashboard, safe to open anywhere. The buttons below are drawn but inert — recording a verification and being refused the release is a state change, so it runs on the live app: python src/demo.py --serve.
- From
- payments@fa1conindustri.com
- Received
- 28 Jun 2026, 22:12
- Subject
- INV-4827
- Reply to
- not a reply
- Thread
- THR00070
Lookalike domainFirst email ever from this sender
The message
Hi there,
The facility you have on file was with our previous banking partner, whose relationship with us ended last week. Everything reaches 589503646822 (SBIN0980627) from here.
INV-4827 from October is still open on our ledger, and the retainer runs through March — both are handled under the arrangement above.
Our GST registration is 27ZVMQQ1156X1Z0.
The amount due is Rs 14,608.
This is the last item before our books close for the year.
Regards,
Rohit Menon
Falcon Industries
What the mailbox history shows
result
check
finding
Concern
First email ever from this sender inbox_first_contact
no earlier message from this sender is in the mailbox — a first contact asking about a payment destination
from Mailbox history
Everything here is Tier 2. A mailbox owner can send themselves messages and build a thread to any depth, so this evidence may hold a payment and can never release one.
What the sender resolved to
- Supplier
- VEND0096
- Matched on
- Lookalike domain
- Because
- built to be mistaken for this supplier's real domain
- Domain matched
- falconindustri.com
- Triage decision
- Needs review
- Change request filed
- doc_61edd1594d2d93da
mentions an account, a bank or a settlement destination
Sender matching decides whether a message is read in full. It never decides a payment on its own — a lookalike domain is a reason to look, not a reason to reject.
What happens to the payment
Released
Routine payment — nothing was being changedR2a_no_change_confirmed