Static snapshot. A frozen copy of the operator dashboard, safe to open anywhere. The buttons below are drawn but inert — recording a verification and being refused the release is a state change, so it runs on the live app: python src/demo.py --serve.

BaseDrift

INV-4827
← Inbox
From
payments@fa1conindustri.com
Received
28 Jun 2026, 22:12
Subject
INV-4827
Reply to
not a reply
Thread
THR00070
Lookalike domainFirst email ever from this sender

The message

Hi there, The facility you have on file was with our previous banking partner, whose relationship with us ended last week. Everything reaches 589503646822 (SBIN0980627) from here. INV-4827 from October is still open on our ledger, and the retainer runs through March — both are handled under the arrangement above. Our GST registration is 27ZVMQQ1156X1Z0. The amount due is Rs 14,608. This is the last item before our books close for the year. Regards, Rohit Menon Falcon Industries

What the mailbox history shows

result
check
finding
Concern
First email ever from this sender
inbox_first_contact
no earlier message from this sender is in the mailbox — a first contact asking about a payment destination
from Mailbox history

Everything here is Tier 2. A mailbox owner can send themselves messages and build a thread to any depth, so this evidence may hold a payment and can never release one.

What the sender resolved to

Supplier
VEND0096
Matched on
Lookalike domain
Because
built to be mistaken for this supplier's real domain
Domain matched
falconindustri.com
Triage decision
Needs review
Change request filed
doc_61edd1594d2d93da
mentions an account, a bank or a settlement destination
Sender matching decides whether a message is read in full. It never decides a payment on its own — a lookalike domain is a reason to look, not a reason to reject.

What happens to the payment

Released
Routine payment — nothing was being changed
R2a_no_change_confirmed