phishtriage

For everyone · 4 minutes

Check an email

Got an email that doesn’t feel right? PhishTriage can give you a second opinion on whether to trust it. It takes one click, and the answer usually comes in a few seconds.

Where this works

PhishTriage checks emails in Gmail and Outlook when you read them in your web browser. Look at the address bar at the top of your browser. The address should start with one of these:

Reading your email somewhere else? See If you read email somewhere else below.

Check an email, step by step

  1. Open the email you’re unsure about, so you can read it. Don’t click its links or open its attachments yet.

  2. Click the PhishTriage icon at the top right of your browser. It’s a small drawing of a shark. If you can’t see it, click the puzzle-piece icon first, then PhishTriage.

    A small window opens. Near the top it says Gmail detected or Outlook detected.

    The PhishTriage window in Gmail. The button to click is the highlighted blue one. In Outlook, the box says Outlook detected instead.
  3. Click the blue button, Analyze Current Email. The small window closes, and a panel opens on the right side of the page.

  4. Wait a few seconds. While PhishTriage checks, the panel shows a moving picture and the word Scanning. Then the answer appears in large coloured letters.

  5. Read the answer. Understand the answer explains what each answer means and what to do next.

At the top of the panel, a box called Content Detected shows what PhishTriage read. It lists who the email is from, who it went to, the subject, the links and the names of any attached files. Check that it’s the email you meant.

You may also see a PhishTriage button in your email

Inside Gmail or Outlook, you may also see a small blue button with the word PhishTriage among the email’s own buttons. Clicking it does the same as Analyze Current Email. If you don’t see it, use the PhishTriage icon as above.

Checking another email

Open the next email. Then click the PhishTriage icon and Analyze Current Email again. Each click checks the email that’s open at that moment.

To close the panel, click the ✕ at its top right.

Already clicked a link or typed a password? Don’t panic. What if I already clicked? takes you through the next steps.

What PhishTriage reads, and what it doesn’t

PhishTriage reads nothing in your email until you click. When it checks an email, it never opens attachments.

Before you click, PhishTriage keeps its button ready on the addresses at the top of this page. It reads none of your emails and sends none of them. But some settings send us things without a click:

When you click, it reads only the email that’s open on your screen. It sends these parts of it to PhishTriage to be checked:

It reads only the names of attachments, such as “invoice.pdf”. It never opens the files themselves. It doesn’t read the rest of your inbox. And when it checks an email, it never takes a picture of what you can see in that tab, or a copy of the page’s code.

PhishTriage keeps a record of each check for a year, then deletes it automatically. You, or your team’s owner, can choose a shorter time, from 7 days up, for checks made after the choice. Checks made before 4 October 2026 are deleted after 90 days. Our server’s log also notes each check. Its line includes your internet address (your IP address), and enough to work out who sent the email. It does not include the words of the email. Nothing in PhishTriage deletes this log automatically. If you ask, we clear your lines by hand: write to privacy@phishtriage.com. What PhishTriage sees explains where this information goes, who can see it and what to tell us.

If you read email somewhere else

Outlook at outlook.cloud.microsoft

Microsoft also runs Outlook at an address that starts with outlook.cloud.microsoft. PhishTriage can’t check an email on its own there.

If you click the PhishTriage icon there, the window says Page detected. Its button says Analyze Current Page. That button checks the whole Outlook page, as if it were an ordinary website. It reads the text of the page, which includes your list of emails, not just the one you opened. So its answer is about the page, not about that email.

Because Outlook counts as a website there, one more thing applies. If the answer is “Don’t trust this” or “Be careful”, PhishTriage also sends us two things. One is a picture of what you can see in that tab. The other is the page’s code. The picture shows your inbox. The code includes the email you had open. That happens unless you have switched off Keep evidence of phishing under Settings in the PhishTriage window.

What you can do instead:

If you already opened a link from the email, don’t go back to that page to check it. If you typed something into it, a check could send us a picture of what you can see in that tab. It could also send us the page’s code. Both could show what you typed. See What if I already clicked?

Email programs and phone apps

PhishTriage works only inside your web browser on a computer. It can’t check emails in a mail program or app. That includes the Outlook program on your computer, Apple Mail, and the mail app on your phone.

Instead, open the same email in your web browser on a computer:

  1. Go to your email’s website and sign in as usual. For Gmail, that’s mail.google.com. For an Outlook.com, Hotmail or Live address, it’s outlook.live.com. For Outlook at work or school, try outlook.office.com.

  2. Find the same email and open it.

  3. Check it as described above.

If the address changes to outlook.cloud.microsoft after you sign in, see the section above.

Other email websites

Some people read email on other websites, such as Yahoo Mail or their employer’s own webmail. There, PhishTriage treats the page like any other website. It can check the page with Analyze Current Page, but not the email on its own. If a check there comes back “Don’t trust this” or “Be careful”, PhishTriage can also send us a picture of what you can see in that tab, and the page’s code. The picture shows your inbox, and the code includes the email you had open. To stop this, switch off Keep evidence of phishing under Settings in the PhishTriage window.