Open your inbox. You receive dozens of emails every day. Which ones are trustworthy? Which are phishing attempts? Which are impersonation scams pretending to be your boss?
Traditional email clients can't answer these questions. The m ail list only shows the sender's name and subject line , no identity information whatsoever. Because the traditional email protocol (SMTP) was designed in the 1980s, the sender address can be forged at will, and there is no mechanism to verify "who really sent this email."
In ZTmail's inbox, every email comes with an identity badge, as shown below. It not only indicates that the email is encrypted and digitally signed, but also shows which algorithm was used (e.g., RSA or SM2 , or PQC ). Most importantly, it displays the T4 icon — the Sponsor validated icon . Clicking on this icon reveals detailed sender identity information, clearly telling the recipient: "the sender's organization identity and individual identity — name — have all been v alidated ." The organization identity also includes the organization's registration number and location.
When viewing an email, recipients can easily determine whether it is trustworthy or suspicious , no technical knowledge required.
The CA/Browser Forum S/MIME Certificate Working Group defines four identity validation levels. ZTmail fully implements them in the recipient-side visualization:
What recipients see is no longer just "this email has a digital signature," but "who sent it, with what identity, and whether the content has been tampered with" , three questions, answered at a glance.
Every email that carries an identity icon instantly strengthens the recipient's trust online, helping to facilitate more transactions and communications.
Why can't other email clients identify the sender?
The email sender addresses can be forged at will. This is a design flaw in the SMTP protocol , it is only responsible for "delivering mail from A to B," not for "verifying who A is."
SPF, DKIM, and DMARC solve some of these problems, but they primarily verify the "server" identity, not the "sender" identity. An email passing SPF/DKIM checks only proves that it came from an authorized server , not that the sender is who they claim to be.
Digital signature technology (S/MIME) solves this: the sender signs with their private key, and the recipient verifies with the sender's public certificate. If an email lacks a digital signature, or if the signature verification fails, the recipient's email client should display a clear warning.
But traditional email clients offer very limited support for digital signatures , either they don't display them at all, or they only show a vague "signature" icon. Users have no idea what level of identity stands behind that signature.
ZTmail turns identity information from "technical detail" into "user interface."
Beyond identity display, ZTmail's AI Assistant actively helps you detect potential fraud and phishing emails . P rovided you have configured your own AI service provider's API key and related parameters.
The AI Assistant automatically analyzes email characteristics to identify suspicious signals:
The AI Assistant automatically scans email content to identify fraud indicators:
In 2026, AI-generated phishing emails already account ed for 86% of all phishing emails. These emails are grammatically flawless, contextually relevant, and far more difficult to detect with the naked eye. The traditional approach of "looking for spelling mistakes" is no longer reliable. The AI Assistant's automatic detection capability is the critical defense against this new threat.
⚠️ Security Alert: This email has the following risks:
Recommendation : Proceed with caution. Do not click links or provide personal information.
Below is an example of a fraudulent email after AI analysis: Highly suspicious. This is a typical financial phishing/scam email. The attacker is likely mass-sending this within the target organization, tricking the finance department into joining a fake social media group. The next step will be impersonating the company executive to demand an "urgent deposit" or "an annual acco unt review" transfer.
Identity display allows users to actively judge email trustworthiness: emails with digital signatures display identity levels clearly; emails without digital signatures are clearly marked as "Identity Not V alidated".
AI detection provides passive defense: automatically detecting anomalies and proactively alerting users to risks.
Together, they leave phishing and fraudulent emails with nowhere to hide.
Traditional email clients tell you "you have mail".
ZTmail tells you , "who sent it, with what identity, and whether it is trustworthy."
Who sent this encrypted email? Identity level, clear at a glance. Who sent this fraudulent email? AI detects it, alerts you automatically.
Upgrade to the Trusted Identity Edition, and let every recipient see your trusted identity.
💡 For guidance on choosing which identity to send with, see our companion article: Choose What Level of Identity to Send With — Four Identities, Four Levels of Trust →