NeoShield Security logo NeoShield Security Quantum X
Sign in to run this tool AI analyses and live lookups run on a metered service, so an account is required. Signing in is free, needs no credit card, and gives you a higher daily allowance than anonymous use ever did. Sign in or create an account

// ai phishing triage

Is this email a phish?

Paste a suspicious email — headers and body — and get a verdict, the specific red flags, defanged links, and recommended actions. Analysis runs in memory only; nothing is stored.

Engine: Claude 1/1 analyses left today (visitor)

Don't paste real passwords or one-time codes. Links are shown defanged and are never visited.

URL-only analyzer

Frequently asked questions

How do I know if an email is phishing?

Common red flags include mismatched sender domains, urgent or threatening language, unexpected attachments, look-alike links, and requests for credentials or payment. The analyzer highlights each signal it finds.

Is it safe to paste a suspicious email here?

Yes. Links are defanged so they cannot be clicked accidentally, and the content is analyzed for your session only — it is not stored or shared.

What does the AI verdict mean?

It is a defensive risk assessment summarizing why the message looks safe, suspicious, or malicious, along with the indicators that drove the conclusion.

What should I do with a confirmed phishing email?

Do not click links or open attachments, report it to your security team or mail provider, and delete it. If you already interacted, run an exposure check and reset affected credentials.

How your input is handled

Processing

The email you paste is analyzed for this one request. NeoShield does not store or log the message body, headers, or any address it contains. The material you submit is sent to the AI provider for this one analysis and is not used to train models.

What we never keep

  • Offline analyzer input is not stored or logged.
  • No model-authored code is executed on NeoShield servers.
  • Credentials, tokens, and payloads you paste are never written to disk by these tools.

Full detail on the Trust page and in the Privacy policy.

What this tool does — and does not — check

It checks

  • Sender authenticity signals: From vs Reply-To vs Return-Path mismatch.
  • Display-name impersonation and look-alike (homograph) domains.
  • Urgency, authority, and payment-redirection social-engineering patterns.
  • Embedded URLs, which are extracted and shown defanged — never visited.
  • Attachment names and types referenced in the headers.

It does not check

  • It does not open, download, or detonate attachments.
  • It does not visit or resolve the links it finds.
  • It does not verify SPF, DKIM, or DMARC against live DNS — it reads what the headers claim.
  • It cannot confirm an email is safe; a clean verdict is not a guarantee.

How it works

  • Headers and body are parsed locally to extract senders, URLs, and structural signals.
  • Those signals are scored by an AI analyst prompt constrained to defensive triage only.
  • When the AI provider is unavailable, a deterministic local heuristic produces the verdict instead, so the tool always returns something explainable.
  • Every indicator carries a severity and a plain-language reason — never an opaque score.
MITRE ATT&CK: Phishing (T1566)NIST SP 800-177

Related tools

Need higher limits?

The Free plan includes a limited number of AI analyses per day on each tool. Pro raises the daily and monthly allowances across every AI tool, unlocks the advanced modules, and is a prepaid pass — it expires on its own, with no automatic renewal.

How to use AI Phishing Email Analyzer Manual & worked example — inputs, output, limits, what it does not do, and a worked example. Open the reference →