Not sure if an email is real or a scam? Paste it below and we'll check it for common phishing and scam indicators — sender spoofing, suspicious links, pressure tactics, credential and payment requests, and more.
Privacy first: Your email content is analysed locally in your browser wherever technically possible and is never stored. Please never paste passwords, authentication codes, payment card numbers or other highly sensitive information into this or any online tool.
You can paste the full raw email including headers, or just the visible text from your inbox.
Headers can help identify where an email actually came from and whether SPF, DKIM and DMARC authentication passed. In Gmail: ⋮ → Show original. In Outlook: File → Properties → Internet headers.
We check the email for common scam and phishing indicators. This is an automated risk assessment, not a guarantee that an email is safe.
We need more of the email, especially the sender, subject, links or headers, to perform a meaningful analysis. Try pasting more of the message, adding the headers, or uploading the .eml file.
Important: This tool provides an automated security assessment and cannot guarantee that an email is legitimate or malicious. When money, passwords, account access, or personal information are involved, independently verify the request before taking action.
Phishing emails are designed to look like they come from someone you trust — a bank, a well-known brand, your employer, or even a colleague — in order to trick you into clicking a link, opening an attachment, or replying with sensitive information. They rely on a mix of technical tricks (spoofed sender addresses, lookalike domains, disguised links) and psychological pressure (urgency, fear, curiosity, reward) to get you to act quickly instead of carefully.
The "display name" of an email — the friendly name you see before the address — can be set to anything the sender wants, including "Microsoft Support" or your bank's name. It has no connection to the actual sending domain, which is why this tool always checks the real address behind the display name.
The blue underlined text of a link can say anything — "paypal.com", "Click here to verify" — while the actual destination is a completely different domain. Always check where a link really goes before clicking, and never rely on the visible text alone.
Scammers create artificial time pressure — "act within 24 hours", "your account will be suspended" — specifically to stop you from pausing, thinking, or checking with someone else. Genuine organisations rarely demand instant action by email.
No genuine bank, employer, or service provider will ever ask you to email your password, PIN, or one-time authentication code, or enter it via a link in an unsolicited message. Any request like this should be treated as a major red flag.
There is rarely a single, definitive sign that an email is a scam. Instead, genuine phishing and fraud attempts tend to combine several weaker signals — a slightly-off domain name, a link that doesn't quite match, some urgency in the wording, a request that's just a little unusual for that sender. This is why this tool doesn't rely on a single keyword or rule; it weighs up sender details, links, wording and (where available) authentication results together, the same way an experienced analyst would.
Some checks worth doing yourself on any email that feels slightly off: does the sending domain actually belong to the organisation it claims to be from? Does hovering over (or long-pressing) a link show a destination that matches what the text says? Is the message asking you to do something unusual under time pressure — pay an invoice to a "new" bank account, verify your password, or provide a one-time code? Would this organisation normally contact you this way?
Remember that authentication passing (SPF, DKIM, DMARC) proves who technically sent the message and that it wasn't altered in transit — it does not prove the message itself is safe. A hacked but genuine account can pass every authentication check while sending a phishing link.
It runs entirely in your browser and checks the sender address, display name, links, wording and (optionally) email headers against dozens of known phishing and scam patterns — sender impersonation, lookalike domains, mismatched links, urgency and pressure language, credential and financial requests, and SPF/DKIM/DMARC authentication results — then combines the evidence into a single risk score with a plain-English explanation for every flag.
It can flag many common phishing indicators — spoofed display names, mismatched sender domains, suspicious or mismatched links, credential requests and pressure tactics. But no automated tool can guarantee an email is or isn't a scam with certainty. Always treat the result as guidance to help you decide, not a final verdict.
No. The email content you paste or upload is analysed locally in your browser and is never uploaded, logged or stored on any server. Nothing about the message you check is retained after you leave or clear the page.
Yes. A genuine account can be compromised and used to send phishing emails, and authentication checks like SPF, DKIM and DMARC passing does not prove the content of an email is safe — it only proves who technically sent it, not what's inside it.
Don't click any links, open attachments, or reply. Don't provide passwords, codes or payment details. Contact the organisation directly using a phone number or website you already trust — never the contact details contained in the suspicious email itself.
No. They prove the email was sent from a server authorised by the claimed domain and generally wasn't altered in transit — but they say nothing about whether the content is a scam, or whether the sending account itself has been compromised or misused.
A phishing email is a message designed to trick the recipient into revealing sensitive information, making a payment, or installing malware — usually by impersonating a trusted organisation or person and creating a sense of urgency or reward.