Antispam MxGuard Business Product information New

When Claude takes a second look: the LLM layer

Transcom 23 Jul 2025, 19:48

Most mail is decided by the LightGBM classifier in milliseconds. The messages that matter most, however, are the borderline ones — well-written, targeted attacks that a statistical model finds ambiguous. Those are handed to the second layer of the AI brain: Claude, Anthropic's large language model.

When it triggers. Claude evaluates the roughly 5% of mail that scores in the uncertain band (0.50–0.95). Rather than looking at features, it reads the message body and headers the way a person would.

What it assesses. Intent, urgency cues, impersonation patterns, lookalike-domain references and call-to-action patterns. This is exactly the territory where legacy filters fail: CEO impersonation, invoice redirection and AI-written phishing with perfect grammar carry no obvious spam signals, but they read as manipulative to a language model.

Transparent verdicts. Every Claude verdict comes with written reasoning that is logged and shown inline in the console and quarantine views, so you can always see in plain English why a message was tagged, quarantined or rejected.

Your mail is never training data. Customer mail is used only to make a verdict on that message. It is never used to train the models.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts