Skip to content
— ✱ FREE TOOL · AI · NO SIGNUP

Is this email phishing?

Paste a suspicious email. Get a forensic verdict in 12 seconds.

We strip HTML, refuse anything that looks like an API key, and sandbox the email so it can't prompt-inject our analyst. The buttons below load TEST templates — they are not real attacks against you.

Test templates:
How this works
  • What you get: a phishing probability verdict, the psychological tactics the attacker used, every suspicious URL extracted, From / Reply-To / Return-Path mismatch analysis, and concrete "if you already clicked" steps.
  • Sandboxed input: the email is wrapped in sentinels and our analyst is instructed to treat it as evidence, never as instructions. Phishing emails that contain "ignore previous instructions" payloads cannot hijack the scan.
  • Auto-refused: we will not analyse pastes that contain anything that looks like an API key, JWT, or private key. Rotate immediately if we flag one.
  • Privacy: raw emails live 90 days for anon, lifetime for signed-in users. Headers are stored hashed for cross-scan analytics. We never train on your data and the result page is never publicly shareable.
  • Engine: Claude Sonnet 4.6. Typical scan ~10–14 seconds. We use Sonnet, not Haiku, because phishing analysis rewards depth.