phishtriage

For everyone · 4 minutes

Turn on Background protection

With Background protection on, PhishTriage checks each site you open and warns you if it is known to be dangerous. It is off until you turn it on.

What it does

Each time you open a website, PhishTriage checks the site’s name, for example example.com. If the site is known to be dangerous, a full-page PhishTriage warning covers the page within a few seconds. Its heading says “PhishTriage detected dangerous site”.

By default it sends only the site’s name, not the full address. It does not send what is on the page either; that only happens when you press Analyze Current Page yourself.

Turn it on

  1. In the top-right corner of your browser, click the PhishTriage icon. A small PhishTriage window opens.

    If you can’t see the icon, see Something isn’t working.

  2. Below the blue Analyze button, click Settings. The settings open underneath.

  3. The first switch is Background protection. Click the switch.

    Background protection is the first switch under Settings. When it is on, the switch is blue. More settings follow below it; you don’t need to change them.
  4. Your browser may now ask if PhishTriage can have more access. If it asks, choose to allow it.

    This message comes from your browser, not from PhishTriage, and its words depend on your browser. It may mention your browsing history and the data on the websites you visit. That sounds alarming, but it is expected. PhishTriage needs this access to see which site each tab opens. It also needs it to put the warning on a dangerous page.

    If no message appears, you allowed it before. Go on to the next step.

  5. Check that the Background protection switch is blue. If the PhishTriage window closed, click the icon and open Settings again to look. If the switch isn’t blue, click it again.

If you say no to your browser’s question, nothing else changes. Background protection simply stays off, and the switch moves back. You can try again whenever you like.

When you installed PhishTriage, a Welcome page opened. On that page the same switch is called Enable threat monitoring. It is the same setting, so you only need to turn it on in one place.

If you see Managed next to the switch and can’t move it, your organisation has set it for you. Ask your IT team.

Try it safely

PhishTriage always treats one harmless page as dangerous, so you can see the warning without any real risk. Your computer recognises this page by itself; it does not depend on a real threat.

  1. Make sure Background protection is on.

  2. Open this page: https://phishtriage.com/dangerous-example

  3. Wait a few seconds. PhishTriage’s full-page warning appears over the page.

  4. Click Go back to safety. You come back here.

If no warning appears, reload the test page once. If there is still no warning, check that the switch is blue.

What the warning looks like

The warning as it looks on the safe test page. On a real warning, the line next to Target shows that site’s address. Go back to safety is the large red button.

The warning says the site may try to steal your passwords, install harmful software, or trick you into giving away personal details. The PhishTriage icon in your toolbar also shows a red ! on that tab.

You have three choices:

The warning appears after the page has loaded. It covers the page, but it does not stop it: the dangerous page is already open underneath. So don’t type passwords, card numbers or other details into it, and don’t download anything from it. Click Go back to safety, or close the tab.

If you already typed something into a page like this, see What if I already clicked?

What it can’t do

Background protection warns only about sites PhishTriage already knows are dangerous. A brand-new scam site may not be known yet, and if PhishTriage can’t be reached, you see no warning and no error. So no warning does not prove a site is safe.

If a page asks for a password, card details or money and you are unsure, check it yourself: Check a website.

“Send full URLs” is a different switch

Under Advanced, near the bottom of Settings, there is a separate switch called Send full URLs. It is off unless you turn it on.

It sends the whole address of every page you open, not just the site’s name. A full address can show which page you read, what you searched for, and sometimes your account name. While it is on, PhishTriage checks every page you open, even if Background protection is off.

Most people should leave it off. Background protection works without it.

Turn it off

  1. Click the PhishTriage icon. A small window opens.

  2. Click Settings. More options appear.

  3. Click the Background protection switch. It is no longer blue. From the next page you open, sites are no longer checked, unless Send full URLs is on (next step).

  4. If you turned on Send full URLs, click Advanced. More options appear.

  5. If the Send full URLs switch is blue, click it. It is no longer blue.

Turning the switch off does not take back the access you gave PhishTriage earlier. To take that back too, open your browser’s extensions page. In Chrome, Edge or Brave, type chrome://extensions in the address bar, then open PhishTriage’s Details. In Firefox, type about:addons, then open PhishTriage and its Permissions. There, turn off the access PhishTriage asked for.