Phishing e-mail checker

Paste a suspicious e-mail and the tool evaluates typical phishing signs right in your browser: a fake sender, links leading somewhere other than they show, spoofed and shortened domains, failed SPF/DKIM verification, pressure language and risky attachments. You get a risk score and a clear list of exactly what is suspicious. For the most accurate result, paste the full e-mail source (in Gmail Show original). A detailed guide on how to check an e-mail by hand (sender, headers, SPF/DKIM) is in our article how to verify a suspicious e-mail. How to spot a scam is also covered in phishing and fraudulent e-mails and scam messages.

🔒 Everything is analysed directly in your browser. The e-mail never leaves your device and is not sent anywhere.

Frequently asked questions

How does the tool tell an e-mail is a scam?
It evaluates typical phishing signs: a mismatch between the sender’s name and address, links leading somewhere other than they show, spoofed and shortened domains, failed SPF/DKIM/DMARC, pressure language, requests for a password or code, and risky attachments. From these it builds a risk score and lists exactly what it objects to.
Is my e-mail sent to a server anywhere?
No. The whole analysis runs directly in your browser via a script on the page. The e-mail content never leaves your device, is not sent anywhere and is not stored. So you can safely evaluate even a sensitive message.
Does a low score mean the e-mail is definitely safe?
No. The tool is a helper and awareness aid, not a guarantee. It works on typical signs, so a well-crafted, targeted attack can slip through. Always weigh the context too: were you expecting such a message, and from this sender?
What should I paste for the best result?
Ideally the full e-mail source. In Gmail you get it via Show original, in Outlook via View message source. The source contains the headers with the sender and the SPF/DKIM results, so the check is far more accurate than with plain text.
Why does it flag an e-mail that is genuine?
Some legitimate messages carry signs that phishing abuses: newsletters using link shorteners, marketing with urgent language or bulk greetings. That is why the result is indicative. The overall picture decides, not a single signal.
I clicked a link in a suspicious e-mail. What now?
If you entered any details, change your password immediately, contact your bank for payment details and enable two-factor authentication. If unsure, we are happy to help secure your accounts and device.