Fake Microsoft OWA / corporate portal login page hosted on *.softr.app phishing lure
softr-owa-portal-lure
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Fake Microsoft Outlook Web App (OWA) / corporate portal sign-in page hosted on a Softr.io free-tier subdomain (*.softr.app). Softr is a no-code web app builder; its free plan allows publishing at <org-name>.softr.app, sharing the softr.app HTTPS certificate and CDN reputation. Attackers publish a pixel-perfect OWA / M365 login form at a custom subdomain and send an email claiming the recipient's corporate email quota is full, their password has expired, or IT requires re-authentication. The *.softr.app domain borrows Softr's certificate authority trust, making the HTTPS padlock appear legitimate. The signal fires when: (1) a link to *.softr.app appears in the body AND (2) an OWA / Outlook / Microsoft 365 / corporate password-expiry or IT-re-authentication narrative is present AND (3) sender is NOT microsoft.com, office.com, microsoftonline.com, or softr.io. Distinct from the Microsoft-impersonation billing-phish family — this specifically targets the Softr no-code hosting abuse vector for enterprise credential harvest. Source: GC1 R12 council #3; Cofense M365 credential phishing 2025; APWG no-code hosting abuse track 2025.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started