The other module of LibraCyber ESG Account Takeover Protection is the Mail Intercept module. Mail Intercept service identifies suspicious outbound messages based on your appliance historical data. The source and destination of a message is checked against the Antispam Engine history and optionally against the Adaptive Trust Engine, in order to detect unusual traffic..
When an internal user sends an email to a new recipient, the message will be intercepted and held in a temporary quarantine for the Hold duration time and the sender is (optionally) notified. During this time, the sender of an outgoing message can recall it or force immediate delivery as shown below. The email will be automatically released and delivered when the Hold duration time expires.