// ai phishing triage
Is this email a phish?
Paste a suspicious email — headers and body — and get a verdict, the specific red flags, defanged links, and recommended actions. Analysis runs in memory only; nothing is stored.
Frequently asked questions
How do I know if an email is phishing?
Common red flags include mismatched sender domains, urgent or threatening language, unexpected attachments, look-alike links, and requests for credentials or payment. The analyzer highlights each signal it finds.
Is it safe to paste a suspicious email here?
Yes. Links are defanged so they cannot be clicked accidentally, and the content is analyzed for your session only — it is not stored or shared.
What does the AI verdict mean?
It is a defensive risk assessment summarizing why the message looks safe, suspicious, or malicious, along with the indicators that drove the conclusion.
What should I do with a confirmed phishing email?
Do not click links or open attachments, report it to your security team or mail provider, and delete it. If you already interacted, run an exposure check and reset affected credentials.
How your input is handled
Processing
The email you paste is analyzed for this one request. NeoShield does not store or log the message body, headers, or any address it contains. The material you submit is sent to the AI provider for this one analysis and is not used to train models.
What we never keep
- Offline analyzer input is not stored or logged.
- No model-authored code is executed on NeoShield servers.
- Credentials, tokens, and payloads you paste are never written to disk by these tools.
Full detail on the Trust page and in the Privacy policy.
What this tool does — and does not — check
It checks
- Sender authenticity signals: From vs Reply-To vs Return-Path mismatch.
- Display-name impersonation and look-alike (homograph) domains.
- Urgency, authority, and payment-redirection social-engineering patterns.
- Embedded URLs, which are extracted and shown defanged — never visited.
- Attachment names and types referenced in the headers.
It does not check
- It does not open, download, or detonate attachments.
- It does not visit or resolve the links it finds.
- It does not verify SPF, DKIM, or DMARC against live DNS — it reads what the headers claim.
- It cannot confirm an email is safe; a clean verdict is not a guarantee.
How it works
- Headers and body are parsed locally to extract senders, URLs, and structural signals.
- Those signals are scored by an AI analyst prompt constrained to defensive triage only.
- When the AI provider is unavailable, a deterministic local heuristic produces the verdict instead, so the tool always returns something explainable.
- Every indicator carries a severity and a plain-language reason — never an opaque score.
Related tools
Need higher limits?
The Free plan includes a limited number of AI analyses per day on each tool. Pro raises the daily and monthly allowances across every AI tool, unlocks the advanced modules, and is a prepaid pass — it expires on its own, with no automatic renewal.