MYTHOSCORTEX

🎣 Phishing Detector

Paste a suspicious email below for an instant phishing check. We scan it for the tricks scammers actually use and explain each one so you can spot them yourself next time.

Need to check email link addresses instead of the message itself? Use the URL Scanner, which also checks domain age and can visit the page for you.

Pattern matching runs as you type, entirely in your browser. If a sender's email domain isn't a free provider like Gmail, we also look up just that domain name (never the rest of the email) against public WHOIS/RDAP, DNS, and certificate-transparency records.

🎣

Paste any suspicious email above to scan it.

How to check if an email is phishing

Paste the email text into the box above. This phishing checker instantly scans it against 14checks real scammers actually trip for an instant phishing detection result. Most are instant pattern matching, and a couple look up the sender domain's public registration record. Here's exactly what it checks for and why it matters. No need to paste anything to read these.

  • Urgency / pressure language. Scammers create fake emergencies to stop you thinking clearly.
  • Threatens account suspension or closure. Real companies don't threaten to close accounts over email without prior notice.
  • Asks for passwords, card numbers, or personal info. No legitimate company emails you asking for your password or financial details.
  • Too-good-to-be-true offer. You didn't enter a competition. You didn't win anything. This is bait.
  • No link, just a number to call. "Callback phishing" skips the link entirely, since links get caught by scanners like this one. You call a number staffed by a scammer who then talks you through installing remote-access software or reading out a card number.
  • Generic greeting instead of your name. Your bank knows your name. 'Dear Customer' means they got your email from a breach, not from your account.
  • Impersonates a well-known brand. Fake emails copy logos and wording from PayPal, Amazon, Netflix etc. to look real.
  • Suspicious links or 'click here' with no visible URL. Real links show you where they go. Phishing links hide behind 'Click Here' buttons.
  • Mentions unusual login or suspicious activity. This is designed to panic you. If you're worried, go directly to the app — don't click the email link.
  • Asks you to 'Allow' or 'Grant Access' to an app. OAuth consent phishing tricks you into approving a real permissions screen for a malicious app, which then keeps access to your account even after you change your password. Only approve app access you specifically requested.
  • Reads like bulk marketing, not a personal or official notice. Legitimate security alerts, invoices, and account notices don't usually include marketing language. A mix of the two — an urgent account warning that also says "unsubscribe" — is a mismatch worth noticing.
  • References a specific company or department by name. Worth independently searching for the company name (not by clicking anything in this email) to confirm it's real and that this is genuinely how it operates. Scammers often invent plausible-sounding company names or departments.
  • Claims to represent a company but replies go to a free email address. Real companies use their own email domain, not a free address like @gmail.com or @yahoo.com. This is one of the most reliable signs of impersonation.
  • The sender's own domain's age and mail setup. For non-free-provider senders, we look up the domain's registration age (via WHOIS/RDAP and certificate-transparency logs) and whether it even has working mail servers. A domain that can't receive email or was registered days ago isn't a real company's mail system.

For example, an email reading "Your account will be suspended within 24 hours, click here to verify"trips both the urgency-language and account-threat checks above before you've even looked at the link itself. And a growing trend is skipping the link entirely: an email that just says "call us immediately at [number] to avoid suspension" is callback phishing, designed specifically to slip past link scanners like this one, because a phone number can't be pattern-matched the same way a malicious URL can. If the email does include a link, paste it into the URL Scanner separately for the full lookalike-domain and domain-age checks.

Frequently asked questions

How do I check if an email is phishing?

Paste the full email text into the box above. The checker scans it for the patterns real phishing emails use: urgency language, account-suspension threats, requests for passwords or card details, and more, and explains why each one matters.

The email doesn't have a link, just a phone number to call. Is that safer?

No, it's often worse. "Callback phishing" deliberately skips the link because links get caught by scanners like this one. The number connects to a scammer who talks you through installing remote-access software or reading out payment details over the phone. Treat an urgent phone number the same as an urgent link.

How do I check a link that was in the email?

Use the URL Scanner tool separately. Paste the link there for lookalike-domain, hidden-redirect, and domain-age checks, plus an optional Deep Scan that visits the page for you in a sandboxed browser.

Is my email sent anywhere when I use this tool?

The email text you paste is never transmitted, logged, or stored. That analysis is pure pattern matching in your browser. The one exception: if the sender's domain isn't a free provider like Gmail, we look up the bare domain name itself (never the rest of the email) against public WHOIS/RDAP, DNS, and certificate-transparency records.

How do you know when a domain was registered?

We query public WHOIS/RDAP registry records for the domain's registration date, cross-checked against the earliest publicly-logged TLS certificate as a backup. Domains registered in the last 30 days are flagged as a red flag, and under 6 months as a caution. Brand-new domains are disproportionately used for phishing infrastructure, even before they end up on any blocklist.

Can this tool guarantee an email is safe?

No automated tool catches everything. Treat a clean result as one good sign, not a guarantee, and go directly to the official site or app if you're ever unsure.

What's the difference between a red flag and a warning sign?

Red flags are patterns almost always tied to scams, like urgency language or requests for a password. Warning signs show up in real messages too, so a couple together should raise caution rather than certainty.

Is this a spam filter or an antivirus scanner?

No, it's a plain-English education tool, not a mail-server spam filter or malware scanner. It won't block or quarantine anything. It explains the tricks in whatever you paste so you can learn to spot them yourself next time.