NeoShield Security logo NeoShield Security Quantum X
このツールを使うにはログインしてください AI分析とライブ検索は従量課金のサービス上で動作するため、アカウントが必要です。登録は無料でクレジットカードも不要です。ログインすると、これまでの匿名利用よりも多い1日あたりの利用枠をご利用いただけます。 ログイン / アカウント作成

// ai phishing triage

Is this email a phish?

Paste a suspicious email — headers and body — and get a verdict, the specific red flags, defanged links, and recommended actions. Analysis runs in memory only; nothing is stored.

Engine: Claude 1/1 analyses left today (visitor)

Don't paste real passwords or one-time codes. Links are shown defanged and are never visited.

URL-only analyzer

Frequently asked questions

How do I know if an email is phishing?

Common red flags include mismatched sender domains, urgent or threatening language, unexpected attachments, look-alike links, and requests for credentials or payment. The analyzer highlights each signal it finds.

Is it safe to paste a suspicious email here?

Yes. Links are defanged so they cannot be clicked accidentally, and the content is analyzed for your session only — it is not stored or shared.

What does the AI verdict mean?

It is a defensive risk assessment summarizing why the message looks safe, suspicious, or malicious, along with the indicators that drove the conclusion.

What should I do with a confirmed phishing email?

Do not click links or open attachments, report it to your security team or mail provider, and delete it. If you already interacted, run an exposure check and reset affected credentials.

入力データの取り扱い

処理方法

The email you paste is analyzed for this one request. NeoShield does not store or log the message body, headers, or any address it contains. ご送信いただいた内容は、この1回の分析のためにAIプロバイダーへ送信されます。モデルの学習には使用されません。

保持しないもの

  • オフライン解析ツールへの入力は保存もログ記録もされません。
  • モデルが生成したコードをNeoShieldのサーバー上で実行することはありません。
  • 貼り付けられた認証情報、トークン、ペイロードがこれらのツールによってディスクに書き込まれることはありません。

詳細は信頼性ページおよびプライバシーポリシーをご覧ください。

このツールが確認すること・確認しないこと

確認すること

  • Sender authenticity signals: From vs Reply-To vs Return-Path mismatch.
  • Display-name impersonation and look-alike (homograph) domains.
  • Urgency, authority, and payment-redirection social-engineering patterns.
  • Embedded URLs, which are extracted and shown defanged — never visited.
  • Attachment names and types referenced in the headers.

確認しないこと

  • It does not open, download, or detonate attachments.
  • It does not visit or resolve the links it finds.
  • It does not verify SPF, DKIM, or DMARC against live DNS — it reads what the headers claim.
  • It cannot confirm an email is safe; a clean verdict is not a guarantee.

仕組み

  • Headers and body are parsed locally to extract senders, URLs, and structural signals.
  • Those signals are scored by an AI analyst prompt constrained to defensive triage only.
  • When the AI provider is unavailable, a deterministic local heuristic produces the verdict instead, so the tool always returns something explainable.
  • Every indicator carries a severity and a plain-language reason — never an opaque score.
MITRE ATT&CK: Phishing (T1566)NIST SP 800-177

関連ツール

もっと多くの利用枠が必要ですか

The Free plan includes a limited number of AI analyses per day on each tool. Proにすると、すべてのAIツールで1日あたり・1か月あたりの利用枠が増え、上位モジュールも使えるようになります。前払いのパスなので期間満了で自動的に終了し、自動更新はありません。

How to use AI Phishing Email Analyzer マニュアルと実例 — inputs, output, limits, what it does not do, and a worked example. Open the reference →