Check a website
Not sure about a website? PhishTriage can check the page you’re on. It gives you a second opinion on whether to trust it, with one click.
When to check a page
Check a page whenever something feels off. For example:
- You followed a link from an email, a chat message or a social media post. Now the page asks you to sign in or pay.
- A message said a parcel is waiting, and the page wants a small fee before delivery.
- An online shop you’ve never heard of has prices that seem too good to be true.
- A page that looks like your bank or your email asks for your password.
- A page says your computer has a virus, or that you’ve won a prize.
Check before you type anything into the page. No passwords, card numbers or codes until you’re sure the page is genuine.
Check a page, step by step
Stay on the page you want to check.
Click the PhishTriage icon at the top right of your browser. It’s a small drawing of a shark. If you can’t see it, click the puzzle-piece icon first, then PhishTriage.
A small window opens. Near the top it says Page detected.
phishtriageReadyPage detectedClick Analyze to triage the current page content.▶ Analyze Current Page⚙ SettingsThe PhishTriage window on a website. The button to click is the highlighted blue one. Click the blue button, Analyze Current Page. The small window closes, and a panel opens on the right side of the page.
Wait a few seconds. The answer appears near the top of the panel, in large coloured letters. Understand the answer explains what to do next.
On ordinary websites there is no PhishTriage button inside the page. Always start from the PhishTriage icon. To check another page, go to it, click the PhishTriage icon, then Analyze Current Page again.
If the window closes and no panel appears, you may be on a page that browsers don’t let add-ons read. These include your browser’s own pages, such as its settings or a new empty tab, and add-on stores. PhishTriage can’t check those pages.
Already typed a password or paid? Don’t panic. What if I already clicked? takes you through the next steps.
What is sent when you check a page
For a check, PhishTriage reads nothing from the page until you click Analyze Current Page. Then it sends these parts of the page to be checked:
- the page’s title;
- its full web address. That includes everything after a “?”, which can contain things like a search you typed;
- the page’s text, up to a limit. This includes text the page hides from view, because hidden text can be a sign of a scam;
- up to 15 links from the page.
PhishTriage keeps a record of each check for a year, then deletes it automatically. You, or your team’s owner, can choose a shorter time, from 7 days up, for checks made after the choice. Checks made before 4 October 2026 are deleted after 90 days. Our server’s log also notes each check. Its line includes your internet address (your IP address), and enough to work out which website you checked. It does not include the words of the page. Nothing in PhishTriage deletes this log automatically. If you ask, we clear your lines by hand: write to privacy@phishtriage.com. What PhishTriage sees says what to tell us.
Two optional features, Background protection and File protection (on some browsers only), work on their own once they are on. Both start off, unless your organisation has turned them on for you. For example, Background protection sends the name of each website you open. Turn on Background protection explains it.
A picture of the page, when the answer is bad
One setting, Keep evidence of phishing, is on unless you switch it off. Here is what it does:
- When you check a website and the answer is “Don’t trust this” or “Be careful”, PhishTriage also sends us two things. One is a screenshot: a picture of what you can see in that tab. The other is the page’s HTML: the code the page is made of.
- This lets the dangerous site be reported, so it can be taken down.
- When the answer is “Looks safe”, neither is sent. Both are thrown away.
- It never happens in Gmail, or in Outlook at outlook.live.com, outlook.office.com or outlook.office365.com. Any other webmail counts as a website, including Yahoo Mail and Outlook at outlook.cloud.microsoft. There, the picture would show your inbox, and the code would include the email you had open.
- If you typed something into the page, such as a card number, the picture can show it. Sometimes the page’s code contains it too.
- We keep the picture and the code for 12 months after a “Don’t trust this” answer, and for 30 days after “Be careful”. If a person reviews them and finds the page was not phishing, both are deleted at once. If they find that a “Be careful” page was phishing, both are kept for 12 months instead.
“Be careful” sometimes appears on genuine websites. So a picture and the code of an ordinary page can be sent this way.
To switch it off
Click the PhishTriage icon.
Below the blue Analyze button, click Settings. More options appear.
Find Keep evidence of phishing, and click the switch next to it. The switch is blue when it’s on. After your click, it is no longer blue.
Your choice is saved straight away. If you see Managed next to the switch and can’t move it, your organisation has set it for you. What PhishTriage sees has all the details.