Raven by SecureMailScope
Passive DefenseZero Active Probing · 100% Observational

Raven - Audit Your Email Encryption Without Sending a Single Packet

Most of the world's email still travels like an open letter. Raven passively observes your mail traffic, verifies whether every hop was cryptographically sealed, and produces a confidence-bounded posture score with court-grade forensic receipts.

RRAVEN
SHA256:7f39b2...4a
POSTURE SCOREGRADE B+
78[CI: 71 – 84]

⚠ 1 hop chain unobservable (TLS 1.3)

DOWNGRADE RADARALERT
1Stripping Flow

STARTTLS stripped by peer relay

ENFORCEMENT CHECKDRIFT
2MTA-STS Mismatches

Claimed: enforce · Observed: plaintext

CIPHER HEALTHPQC READY
91%PFS Negotiated

4 MTAs support Hybrid Kyber-768

TRANSIT HOP TOPOLOGY & WEAKEST LINK PINPOINT

PASSIVE RECONSTRUCTION
MX-01
egress.gov.inTLS 1.3 · Grade A
AES-256-GCM (OK)
942 msgs (66%)
RELAY
relay-hub.netTLS 1.2 · Grade B
⚡ STRIPPED TO PLAINTEXT
WEAKEST HOP (34%)
PEER
mail.legacy-corp.orgVULNERABLE (Grade E)

OBSERVED ENCRYPTION RATIO

TLS 1.3 (RFC 8446)72.4%
TLS 1.2 (PFS Ciphers)17.8%
Plaintext / Stripped9.8%
DNS Policy Match:FAIL (MTA-STS Drift)

FORENSIC EVIDENCE & FINDINGS CHAIN

Audit-ready drilldown with exact packet offsets
SEVERITYRULE IDAFFECTED HOSTEVIDENCE OFFSETVERDICTHASH SIGN
CRITICALSMS-STRIP-001mail.legacy-corp.org:25Pkt #1,429 [0x04f2]STARTTLS announcement suppressedsha256:4a8b1...
HIGHSMS-X509-004relay-hub.net:587Pkt #842 [0x01a8]Cert CN mismatch (claims old.internal)sha256:7c91e...
MEDIUMSMS-ENF-002mx-backup.gov.in:25Pkt #1,104 [0x08b4]MTA-STS policy enforce violatedsha256:3d28f...

Passively verifies cryptographic posture across enterprise MTAs and mail relays

Postfix MTAOpen Source MTA
Microsoft ExchangeEnterprise Mail Server
Exim Mail ServerInternet SMTP Server
Google WorkspaceCloud MX Provider
SendmailUnix Transport Agent
Cisco Secure EmailIronPort Gateway
ProofpointEnterprise Email Protection
MimecastCloud Gateway Security
Amazon SESSimple Email Service
OpenSMTPDSecure BSD Daemon
ProtonMail BridgeEncrypted Relay
Zimbra CollaborationSelf-Hosted Suite
Postfix MTAOpen Source MTA
Microsoft ExchangeEnterprise Mail Server
Exim Mail ServerInternet SMTP Server
Google WorkspaceCloud MX Provider
SendmailUnix Transport Agent
Cisco Secure EmailIronPort Gateway
ProofpointEnterprise Email Protection
MimecastCloud Gateway Security
Amazon SESSimple Email Service
OpenSMTPDSecure BSD Daemon
ProtonMail BridgeEncrypted Relay
Zimbra CollaborationSelf-Hosted Suite
The Real Problem

Why Email Transit Security is Broken in the Wild

The Internet was built ~50 years ago where email was designed as an open postcard. Sealing the envelope via STARTTLS is purely voluntary — and in the wild, active attackers silently strip the seal without your knowledge.

30%

of global mail servers present invalid or expired X.509 identity certificates

Active Port Scanners

Intrusive & blocked by firewalls

Passive Observation

100% Non-intrusive & silent

Without passive cryptographic observation, your organization remains blind to

STARTTLS Stripping Attacks

Handshake Command Injection

Silent Plaintext Downgrades

Weak Ciphers & Nonce Reuse

MTA-STS & DANE Drift

SPF, DKIM, and DMARC verify sender identity — they do not guarantee encryption in transit.

Core Capabilities

Everything You Need to Audit Mail Cryptographic Posture

0–100 Confidence-Bounded Posture Score

Deterministic mathematical scoring engine based on NIST SP 800-52r2 and RFC standards. Raven produces an honest score with statistical confidence bands and explicitly declared blind spots — never a black-box guess.

RFC/NIST DeterministicConfidence IntervalsNo Black-Box Hallucinations

Cross-Hop Delivery Graph

Trace the complete journey of your email across every MX hop and relay. Raven calculates traffic-weighted exposure and instantly highlights the single weakest link.

Hop-by-Hop MappingWeakest-Link Pinpoint

Downgrade Radar

State-machine analysis of SMTP handshakes to detect active STARTTLS stripping, command injection, and cipher downgrade anomalies before they cause a breach.

Court-Grade Forensic Evidence Chains

Every finding links directly to the exact flow timestamp, packet number, byte offset, and TLS record index. Backed by SHA-256 signed evidence chains that stand up in legal, regulatory, and forensic security audits.

Exact Packet OffsetsSHA-256 ManifestAudit-Ready Exports

Claim vs. Reality Audit

Compares published DNS policies (MTA-STS, DANE TLSA, TLS-RPT) against real wire traffic. Raven alerts you when an advertised security policy fails in actual transit.

Interactive Incident Replay

Step-by-step forensic animation replaying flagged sessions. Visually inspect when and where negotiation downgraded with exportable WebM evidence recordings.

Air-Gapped & Sovereign Ready

Zero external cloud dependencies. Unplug the network cable, upload a PCAP, and run complete forensic evaluations on isolated defense and enterprise workstations.

Defensive Advantages

Why Security Teams Trust Raven

Designed from first principles to fulfill rigorous defense requirements: non-intrusive observation, transparent math, and courtroom-admissible evidence.

100% Passive Analysis — Zero packets sent to mail servers
Air-Gapped Operation — Works with network cable unplugged
Packet-Level Evidence Chains — Exact byte offsets & flow IDs
STARTTLS Stripping Detection — Automated downgrade alerts
Deterministic RFC/NIST Rubric — Transparent, reproducible math
Zero Content Decryption — Email bodies & creds never touched
Cross-Hop Delivery Graph — Pinpoint the weakest mail relay
MTA-STS & DANE Enforcement — Claim vs reality verification
Automated Remediation Playbooks — Copy-paste configs for Postfix & Exim
Tamper-Evident Evidence — Hash-signed manifests for legal audits
Why Raven Is Unique

What Makes Raven Different

Zero Active Probing

We never knock on servers or send packets. Raven operates as a pure passive observer, safe for covert military and enterprise SOC environments.

Honest Uncertainty

When encryption hides details (like encrypted certificates under TLS 1.3), we declare blind spots rather than pretending everything is fine.

Court-Grade Receipts

Every score, flag, and finding comes with the exact packet offset, byte range, and hash-signed span. No hunches, no opaque numbers — only audit-admissible proof.

Posture Decay Timeline

Monitors cryptographic degradation across time windows. Alerts when a relay drifts from Grade A to Grade D before it is compromised.

100% Offline & Deterministic

Run on air-gapped laptops without internet. The exact same PCAP with the same package version produces bit-for-bit identical report checksums.

Deployment & Sizing

Self-Hosted Air-Gapped Deployment

Raven is self-hosted software that runs entirely within your perimeter. No cloud dependencies, no credential handovers, and 100% passive.

Analyst Workstation

Single-analyst laptop or incident-response rig. Drag-and-drop PCAP ingest and offline evidence generation.

Air-Gapped Standalone
10 Flows / Day (Single Server)1000+ Flows / Day (Fleet Enterprise)
Deployment Edition
Free & Open Source Forever

100% self-hosted on your hardware. Zero data ever leaves your perimeter.

Deterministic RFC/NIST scoring engine
Packet-level byte offset evidence chains
Cross-hop delivery graph mapping
Downgrade radar & STARTTLS state machine
Zero email content or credential decryption
Tamper-evident SHA-256 report verification
Practitioner Verification

Validated by Security Teams & Forensics Leads

AK

Abhishek Kulkarni

Lead SOC Analyst, Sovereign Cyber Defense

“Raven gave our SOC team immediate passive visibility into stealth STARTTLS stripping attacks that our boundary firewalls completely missed. Zero packets sent to external targets.”

VM

Vikram Malhotra

Digital Forensics & Incident Response (DFIR)

“The court-grade evidence chain linking each security finding to the exact packet offset, byte range, and hash signature makes compliance auditing completely unassailable.”

SN

Sneha Nair

Enterprise Infrastructure & Mail Architect

“The Cross-Hop Delivery Graph immediately highlighted that our secondary fallback MX had quietly disabled TLS 1.3. We fixed it with the copy-paste Postfix playbook in 5 minutes.”

RD

Rohan Deshmukh

Security Compliance Auditor

“The deterministic RFC and NIST scoring rubric with honest confidence intervals is refreshing. It tells us exactly what was unobservable instead of handing out false all-clears.”

AK

Abhishek Kulkarni

Lead SOC Analyst, Sovereign Cyber Defense

“Raven gave our SOC team immediate passive visibility into stealth STARTTLS stripping attacks that our boundary firewalls completely missed. Zero packets sent to external targets.”

VM

Vikram Malhotra

Digital Forensics & Incident Response (DFIR)

“The court-grade evidence chain linking each security finding to the exact packet offset, byte range, and hash signature makes compliance auditing completely unassailable.”

SN

Sneha Nair

Enterprise Infrastructure & Mail Architect

“The Cross-Hop Delivery Graph immediately highlighted that our secondary fallback MX had quietly disabled TLS 1.3. We fixed it with the copy-paste Postfix playbook in 5 minutes.”

RD

Rohan Deshmukh

Security Compliance Auditor

“The deterministic RFC and NIST scoring rubric with honest confidence intervals is refreshing. It tells us exactly what was unobservable instead of handing out false all-clears.”

RD

Rohan Deshmukh

Security Compliance Auditor

“The deterministic RFC and NIST scoring rubric with honest confidence intervals is refreshing. It tells us exactly what was unobservable instead of handing out false all-clears.”

SN

Sneha Nair

Enterprise Infrastructure & Mail Architect

“The Cross-Hop Delivery Graph immediately highlighted that our secondary fallback MX had quietly disabled TLS 1.3. We fixed it with the copy-paste Postfix playbook in 5 minutes.”

VM

Vikram Malhotra

Digital Forensics & Incident Response (DFIR)

“The court-grade evidence chain linking each security finding to the exact packet offset, byte range, and hash signature makes compliance auditing completely unassailable.”

AK

Abhishek Kulkarni

Lead SOC Analyst, Sovereign Cyber Defense

“Raven gave our SOC team immediate passive visibility into stealth STARTTLS stripping attacks that our boundary firewalls completely missed. Zero packets sent to external targets.”

RD

Rohan Deshmukh

Security Compliance Auditor

“The deterministic RFC and NIST scoring rubric with honest confidence intervals is refreshing. It tells us exactly what was unobservable instead of handing out false all-clears.”

SN

Sneha Nair

Enterprise Infrastructure & Mail Architect

“The Cross-Hop Delivery Graph immediately highlighted that our secondary fallback MX had quietly disabled TLS 1.3. We fixed it with the copy-paste Postfix playbook in 5 minutes.”

VM

Vikram Malhotra

Digital Forensics & Incident Response (DFIR)

“The court-grade evidence chain linking each security finding to the exact packet offset, byte range, and hash signature makes compliance auditing completely unassailable.”

AK

Abhishek Kulkarni

Lead SOC Analyst, Sovereign Cyber Defense

“Raven gave our SOC team immediate passive visibility into stealth STARTTLS stripping attacks that our boundary firewalls completely missed. Zero packets sent to external targets.”

FAQ

Frequently Asked
Questions

Everything you need to know about Raven's passive observation principles, cryptographic methodology, and air-gapped deployment.

What is Raven and how does it work?
Raven is a passive cryptographic posture assessment platform for email infrastructure. It analyzes passively captured SMTP, IMAP, and POP3 traffic (from PCAP files or network TAP/SPAN ports) to evaluate TLS negotiation, certificate integrity, and downgrade vulnerabilities without sending a single packet.
Does Raven connect to our mail servers or read email contents?
Never. Raven is self-hosted software installed on your own infrastructure. It requires zero mail passwords, never logs into mailboxes, and never touches email bodies or attachments. It inspects only boundary handshake metadata, cipher suites, X.509 certs, and DNS policies.
Why is passive observation better than active scanning?
Active scanners knock on doors from outside, generating loud firewall alerts and failing to reflect actual end-to-end delivery behavior. Active tools cannot observe active TLS stripping happening between relays in the wild. Raven passively watches the authentic traffic flow with zero network noise.
Can Raven operate in air-gapped or classified environments?
Yes. Raven was engineered specifically for air-gapped, zero-internet sovereign environments. All scoring rubrics, cipher intelligence, and reporting engines run completely locally. The entire flow from PCAP upload to signed PDF report works with the network cable unplugged.
What makes Raven's posture score trustworthy?
Most security tools produce opaque numbers without receipts. Raven's 0–100 score is deterministic, mathematical, and mapped directly to NIST SP 800-52r2 and RFC standards. It provides statistical confidence intervals and explicitly declares unobservable metadata rather than assuming it is clean.
How does Raven detect STARTTLS stripping and downgrade attacks?
Raven incorporates a 6-class STARTTLS state machine that tracks the exact negotiation flow between sender and receiver. It detects when an intermediary strips STARTTLS announcements, injects commands, or forces fallback to unencrypted plaintext.
Get Started

Ready to Audit Your Email
Cryptographic Posture?

Drop in a PCAP capture or deploy a passive tap to uncover STARTTLS downgrades, invalid certificates, and weak ciphers across your entire mail path.