phishtriage

For everyone · 4 minutes

Check a website

Not sure about a website? PhishTriage can check the page you’re on. It gives you a second opinion on whether to trust it, with one click.

When to check a page

Check a page whenever something feels off. For example:

Check before you type anything into the page. No passwords, card numbers or codes until you’re sure the page is genuine.

Check a page, step by step

  1. Stay on the page you want to check.

  2. Click the PhishTriage icon at the top right of your browser. It’s a small drawing of a shark. If you can’t see it, click the puzzle-piece icon first, then PhishTriage.

    A small window opens. Near the top it says Page detected.

    The PhishTriage window on a website. The button to click is the highlighted blue one.
  3. Click the blue button, Analyze Current Page. The small window closes, and a panel opens on the right side of the page.

  4. Wait a few seconds. The answer appears near the top of the panel, in large coloured letters. Understand the answer explains what to do next.

On ordinary websites there is no PhishTriage button inside the page. Always start from the PhishTriage icon. To check another page, go to it, click the PhishTriage icon, then Analyze Current Page again.

If the window closes and no panel appears, you may be on a page that browsers don’t let add-ons read. These include your browser’s own pages, such as its settings or a new empty tab, and add-on stores. PhishTriage can’t check those pages.

Already typed a password or paid? Don’t panic. What if I already clicked? takes you through the next steps.

What is sent when you check a page

For a check, PhishTriage reads nothing from the page until you click Analyze Current Page. Then it sends these parts of the page to be checked:

PhishTriage keeps a record of each check for a year, then deletes it automatically. You, or your team’s owner, can choose a shorter time, from 7 days up, for checks made after the choice. Checks made before 4 October 2026 are deleted after 90 days. Our server’s log also notes each check. Its line includes your internet address (your IP address), and enough to work out which website you checked. It does not include the words of the page. Nothing in PhishTriage deletes this log automatically. If you ask, we clear your lines by hand: write to privacy@phishtriage.com. What PhishTriage sees says what to tell us.

Two optional features, Background protection and File protection (on some browsers only), work on their own once they are on. Both start off, unless your organisation has turned them on for you. For example, Background protection sends the name of each website you open. Turn on Background protection explains it.

A picture of the page, when the answer is bad

One setting, Keep evidence of phishing, is on unless you switch it off. Here is what it does:

“Be careful” sometimes appears on genuine websites. So a picture and the code of an ordinary page can be sent this way.

To switch it off

  1. Click the PhishTriage icon.

  2. Below the blue Analyze button, click Settings. More options appear.

  3. Find Keep evidence of phishing, and click the switch next to it. The switch is blue when it’s on. After your click, it is no longer blue.

Your choice is saved straight away. If you see Managed next to the switch and can’t move it, your organisation has set it for you. What PhishTriage sees has all the details.