Is this email a scam? Check it in your browser
Paste a suspicious email. You'll see every warning sign the checks find, why it matters, and what to do. Built for teams handling invoices, payments and sign-in requests.
Runs locally · nothing uploaded
What it checks
- The sender: a Reply-To that sends your answer somewhere else, a display name that shows a different address or a brand the address doesn't belong to, failed SPF, DKIM or DMARC checks, and payment requests from personal email accounts.
- Lookalike domains: the sender and every link compared with 31 frequently impersonated brands and any domains you trust: swapped letters (paypa1, rnicrosoft), look-alike characters from other alphabets, extra words (-secure, -billing), and different endings.
- The words: asks you to pay a new or changed bank account; asks for gift cards or cryptocurrency; asks for a payment or talks about an invoice; pushes you to act fast; asks for secrecy, or says the sender can't be reached; asks you to sign in or confirm a password; asks you to scan a QR code; moves the conversation to a new number or a voice note.
- Links: link text that shows one address but goes to another, shortened links, links to bare IP addresses, and addresses with an @ that hides the destination.
- Attachments: programs, scripts, shortcuts, disk images and web-page attachments (.html, .htm, .svg), double extensions such as invoice.pdf.html, and macro-enabled Office files or archives.
The verdict is Likely scam, Suspicious or No red flags found in these checks. It never says an email is safe: it can only report what it found. The rules are in /scam-rules.js and the checks in /email-check.js, which anyone can read.
If you think it's a scam
- Don't click links, open attachments, reply, or pay from this email.
- Check with the sender on a phone number or address you already have, not one in the email.
- Report it to your IT or security contact, or with your mail app's Report phishing button, then delete it.
- In the UK, forward suspicious emails to [email protected] (NCSC). In the US, report fraud at reportfraud.ftc.gov (FTC).
- If money has already been sent, call your bank straight away to try to stop the payment, then report it at ic3.gov (FBI) or to Action Fraud (UK).
Questions
Is the email uploaded or stored?
No. The check runs in your browser. The page is blocked from connecting anywhere, and nothing is saved: close the tab and it's gone. Even so, remove anything you'd rather not paste, such as account numbers.
Can it tell me an email is safe?
No automated check can prove that. If it finds nothing, it says "No red flags found in these checks". Anything that asks for a payment, a bank-detail change, a password or a gift card still needs a call to the sender on a number you already have.
How do I get the full email with its headers?
Gmail: open the message, then More (three dots) > Show original. Outlook: open the message, then File > Properties (Internet headers), or View message source in Outlook on the web. Apple Mail: View > Message > Raw Source. Copy everything and paste it in.
Can my whole team use it?
Yes, it's free with no sign-up. Share the link, and use "Download the report for IT" to send a finding to whoever handles security.
Want your team to spot these without a tool? The free AI Scam Defense module covers deepfake calls, fake invoices, QR codes and AI-written phishing.
Sources
- UK National Cyber Security Centre (NCSC): Phishing scams: how to spot and report them
- UK National Cyber Security Centre (NCSC): Phishing attacks: defending your organisation
- FBI Internet Crime Complaint Center (IC3): Business Email Compromise: The $55 Billion Scam (Alert I-091124-PSA) (11 September 2024)
- UK National Cyber Security Centre (NCSC): The near-term impact of AI on the cyber threat (24 January 2024)
Sources checked 30 September 2026.