❓ Frequently Asked Questions
What types of phishing does this detect? ▼
Detects various phishing types including credential theft, spear phishing, CEO fraud, invoice scams, account verification scams, tech support fraud, and advance-fee schemes. Analyzes language patterns, sender information, and social engineering tactics.
How accurate is the detection? ▼
Uses pattern matching and heuristic analysis to identify common phishing indicators with high accuracy. While no tool is 100% perfect, it catches most known phishing patterns and social engineering cues. Always use multiple layers of verification.
Is my email data secure? ▼
Absolutely! All analysis is performed locally in your browser. Your email content never leaves your device or gets sent to any server. We don't store, log, or transmit any email data for maximum privacy.
What should I do if an email is flagged? ▼
If flagged as high-risk: Do not click any links, don't download attachments, don't reply. Delete the email immediately. For medium-risk: Verify with the company directly using official contact info. Report phishing to your email provider.
Can it analyze email headers? ▼
Yes, includes analysis of email headers including From, Reply-To, Return-Path, and authentication results. Detects domain spoofing, display name deception, and suspicious routing patterns when full headers are provided.
What are common phishing red flags? ▼
Urgency/threats, generic greetings, spoofed domains, mismatched links, poor grammar, requests for credentials, unexpected attachments, too-good-to-be-true offers, and pressure to bypass normal procedures.
Does it detect AI-generated phishing? ▼
Yes, advanced detection includes patterns common in AI-generated phishing: perfect grammar used deceptively, context-aware personalization, sophisticated impersonation, and hybrid social engineering techniques.
How often is the detection updated? ▼
Detection patterns are regularly updated to catch new phishing techniques and emerging scam patterns. The local analysis engine uses current heuristics for real-time protection without requiring server updates.