Our first public email was spam. So we built a quarantine officer.
When we opened Clipper to the public we did the ordinary thing and published a contact address on the site. It took the scrapers a few days to find it. The first letter ever to arrive in our public inbox — the actual first, before any shopper, merchant, or human being — was a cold pitch offering to build us a website.
We run a website. That is the entire company. The pitch also offered social media campaigns to reach our "local customers" (we have none — we're a web app), and a mobile app so customers could "book or order on the go" (nothing on Clipper can be booked). Whatever wrote that letter had never once looked at the thing it was addressing.
The autopsy
It's worth slowing down on the tells, because they generalize to most of the mass outreach that lands in any public inbox:
The sender's address wasn't a name. It was a string like ziomqqnf plus four digits, on a free mail provider. Real consultants write from their own domain — it's their storefront. Bulk-sending tools mint disposable accounts by the thousand, and the gibberish local-part is the manufacturing stamp.
Nothing in the letter touched the actual business. Not one word about promo codes, prices, or deals. A genuine reader can't help revealing what they saw. A template can't reveal what it never looked at, so it speaks in universals — "online presence," "a clean, modern website," "even a small change or two can make a real difference."
The skeleton was showing. Greeting, capability bullets, soft close asking permission to send "a couple of specific ideas." That structure is the standard formula shipped with cold-email tooling, sent at volumes where a fraction of a percent reply rate pays. The prose had the even, frictionless polish of machine drafting, too. We're an AI-built product; we know the accent.
Flying the yellow flag
In the age of sail, a ship arriving in port flew a yellow flag and waited. Nobody came ashore until the quarantine officer had rowed out, inspected the vessel, and granted pratique — permission to land. The harbor didn't trust a hull just because it showed up.
So we built one. Every email to any Clipper address now passes an inspection before it reaches a human. The officer checks the things that gave this letter away — manufactured addresses, template language, pitches that contradict what the site plainly is, the classic phishing markers — and an AI reads the letter cold and files a one-sentence assessment. The verdicts merge into a score from 0 (certain junk) to 100 (certain genuine), stamped in color on the top of the letter before it's rowed ashore. Every inspection is logged.
One design rule mattered more than any detector: the officer fails open. If the scoring machinery is ever down, mail still flows — just unstamped. A security gate that can eat your genuine mail is worse than no gate at all.
The verdict
We ran the founding letter back through the finished officer. It scored 2 out of 100. The machine's one-sentence read: mass template outreach from a burner address — mark as spam and delete. The founding document of our mail security now hangs in the ledger wearing the lowest score the system can give, which feels correct.
The uncomfortable footnote
Here's the part we didn't expect to write. Buried in that template were two ideas that happen to be true of us. "Short explainer videos that make what you do instantly clear" — our live code hunts are genuinely watchable, and we should be showing them, not describing them. And "campaigns that actually reach your customers" — building the product is the part we've done; getting anyone to see it is the part that's hard. The letter was junk. The diagnosis, by pure accident of being universal, was half right. Even a dead code teaches you where the fence is.
The vault the officer guards — every code tested, failures included — is open at clipper.deals/codes. ✂