Runs on your device · nothing is uploaded
Paste an email or a link. The scanner reads what the email is actually asking you to do, checks whether that fits who sent it and where its links go, and shows you the reasons. Words like “urgent” or “invoice” on their own are not treated as warning signs.
Each sentence is read to find instructions aimed at you: sign in, pay, change bank details, call a number, install software, buy gift cards, keep it quiet. Advice, news, alerts and “don't do this” sentences are not requests.
Signing in at the sender's own, verified website is normal. Signing in on a look-alike or a free hosting page is not. Inside Outlook the sender's authentication (SPF, DKIM, DMARC) is checked too.
Secrecy, “I can't take calls”, a free-mail address for a manager or supplier, or a phone number about a charge you didn't make. Pressure such as “within 24 hours” only matters when one of these is present.
Two machine-learning models also run in your browser: one reads the wording, one examines every link (look-alike domains, raw IP addresses, hidden redirects, risky domain endings). The wording model only supports a verdict; it can't flag an authenticated sender on vocabulary alone. No email content ever leaves your device. Everything downloads once with the page and then works offline.
This is the single-file version of Phishing Scanner: it works offline and keeps everything on your device. The Outlook add-in and the installable app are available from the website version.