Understand the answer
After a check, PhishTriage shows its answer in a panel on the right of the page. Here is what the answer means, and what to do next.
The three answers
Near the top of the panel, in large coloured letters, you’ll see one of three answers.
“Don’t trust this”
PhishTriage thinks this is phishing: a trick to steal your password, your money or your personal details.
What to do:
- Don’t click any links or buttons in it.
- Don’t open any attachments.
- Don’t reply, and don’t call any phone number it gives.
- Don’t type in a password, a code or card details.
- If it came to your work email, tell your IT team. They may want to see it before you delete it.
- Otherwise, delete the email or close the website.
- If it claims to come from a company or person you know, contact them in a way you already trust. Use the phone number on your bank card, their official app, or their website typed in yourself.
Already clicked, or typed something in? Don’t panic. What if I already clicked? takes you through the next steps.
“Be careful”
PhishTriage found warning signs, but isn’t sure it’s a scam. Genuine emails and websites sometimes get this answer too.
What to do:
- Don’t act on it yet. Treat it as possibly dangerous until you have checked.
- Check it another way. Contact the company or person using details you already have. Don’t use the links, phone numbers or addresses in the message.
- Don’t type in a password, a code or card details until you’re sure.
- If you’re still unsure, treat it as “Don’t trust this”. At work, ask your IT team.
“Looks safe”
PhishTriage found no signs of a scam. You can usually carry on as normal.
Still, if it asks for a password, a code, money or gift cards, take a moment to check it another way. “Looks safe” is not a guarantee explains why.
The lines under the answer
- A short explanation. Right under the answer is one line. It’s either a reason PhishTriage found, or a general line such as “Almost certainly a phishing attempt.”
- Who it pretends to be, and what it wants. If PhishTriage spots them, a coloured line says so, for example “Impersonating Microsoft · asking for your password”. “Impersonating” means pretending to be someone else. It may be asking for your password, a payment, your 2FA code or personal details. It may also want you to run a file, buy gift cards, reply, or click a link. A 2FA code is the one-time code you get by text or in an app when you sign in somewhere.
- A small grey tag, such as PHISHING · HIGH CONFIDENCE. It gives the answer’s technical name, and how sure PhishTriage is: high, medium or low. “Phishing” goes with “Don’t trust this”, “suspicious” with “Be careful”, and “benign” (harmless) with “Looks safe”.
The rest of the panel
You don’t need any of this to decide what to do. It’s there if you want to know more. Some labels in the panel are shown in capital letters. From top to bottom:
- Content Detected, above the answer: what PhishTriage read. For an email, that’s From, To, Subject, URLs (the links) and Files (the names of attachments). For a website, it’s Page, URL, Domain (the website’s name) and Links.
- Top signals: up to three things that stood out most, each with a score out of 100, such as “Urgency 85”. It only appears when something scored 40 or more.
- A summary: two or three sentences explaining the answer. PhishTriage’s checking system writes them automatically, usually in English.
- Your feedback: two buttons, explained below.
- Score bars: each bar is a score from 0 to 100. Higher means more worrying. A bar is green below 40, orange from 40 to 69, and red from 70.
- Technical indicators: specific things PhishTriage found, such as a web address, a sender or a trick. Each has a short note. A thin coloured line on its left shows how serious it is: red for high, orange for medium, green for low. This part is mainly for IT staff.
- Re-analyze: checks again. Next to it is the time of the answer.
The score bars you may see are:
- Risk: the overall score.
- Phishing: how much it looks like a trick to steal your details.
- Social Eng.: tricks that play on your feelings, such as fear, hurry or trust.
- Urgency: pressure to act fast.
- Auth: whether the sender, or the website, really is who it claims to be.
- Impersonation: pretending to be a company or person you know.
- Links: how risky its links look.
- Obfuscation: hiding things on purpose, such as lookalike letters or hidden text.
- Attachment: how risky the names of attached files look, or the files a website offers you.
To close the panel, click the ✕ at its top right.
“Looks safe” is not a guarantee
PhishTriage gives you a second opinion, not a promise. Here is what it can and can’t know.
- It judges only what it’s given: an email’s sender, subject, text, links and attachment names, or a page’s address, text and links.
- It never opens attachments, so it can’t see what’s inside a file.
- For an email, it can’t see some hidden details that email services use to confirm who really sent it.
- The answer comes from an automatic check by a computer. It can be wrong both ways. It can miss a new scam, and it can warn about something genuine.
- A website can change after you check it.
So if anything asks for a password, a code, money or personal details, check it another way first. Do this even after “Looks safe”.
Tell PhishTriage what you think
Under the summary is a box called Your feedback, with two buttons:
- Looks safe to me: press this if you believe the email or website is genuine.
- Looks dangerous: press this if you believe it’s a scam.
You can press one of them, once, for each answer. Then both buttons disappear, and this note appears in their place:
Thanks — saved on this device.
The note says where your answer went. In the version of PhishTriage the stores offer now, your answer is saved on your computer only. Nothing is sent to us.
Pressing a button doesn’t change the answer. It doesn’t delete the email or block the website either. If you think PhishTriage got it wrong, you’re welcome to tell us at support@phishtriage.com.
If you see a message instead of an answer
Sometimes the panel shows a short message and a Try again button instead of an answer. This is usually easy to fix. Here is what each message means.
- “Too many scans right now. Give it a moment and try again.” There is a limit on how many checks can run in an hour. Wait a while, then click Try again.
- “Couldn’t reach the service. Check your connection and try again.” PhishTriage couldn’t connect. Check that other websites open, then click Try again.
- “That took too long and was stopped. Try again.” Click Try again.
- “The triage service didn’t respond properly. This is usually temporary.” Wait a minute, then click Try again.
- “That message is too large to scan.” PhishTriage can’t check this one. Follow the steps under “Be careful” above.
- “PhishTriage was updated.” PhishTriage got a new version while the page was open. Nothing was sent. Click Reload page, then check again.
- Any other message, such as “Something went wrong.” Click Try again. If it keeps happening, see Something isn’t working, or write to support@phishtriage.com. If you see Technical detail under the message, click it and copy what it shows into your email. It helps us find the problem.