Paste the text of a suspicious email below and see which common scam warning signs it contains — instantly, in your browser.
Nothing you paste here is stored, logged, or sent anywhere. This tool runs entirely in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you type.
This tool scans the text you paste for common patterns used in phishing and scam emails — urgency and threats, requests for passwords or personal details, mismatched or shortened links, generic greetings, and prize or refund lures. It's a pattern-matching heuristic, not a guarantee: genuine emails can occasionally trip a flag, and well-written scams can avoid them. Use it as one signal among several, not a final verdict.
Yes. Everything happens locally in your browser using JavaScript — the text is never sent to a server, logged, or stored. Disconnect your internet after the page loads and the tool still works, which proves nothing is being transmitted.
Don't click any links or download attachments. Don't reply. If it claims to be from a company or bank you use, contact them directly through their official website or the number on your card — never through a link or number in the email itself.
No — it only analyses the text for common phishing language and patterns. It doesn't open links, scan attachments, or check where a link actually leads. Never click a link to "check" it yourself.
Modern phishing rarely contains typos anymore. Instead it leans on structure: a trusted sender name over a lookalike domain, a plausible pretext (invoice, shared file, security alert), and a single call to action that rewards haste. The email is engineered so that spotting one flaw is not enough — every element looks fine in isolation.
Do not panic, and do not ignore it. If you entered a password, change it immediately — everywhere it is reused — from a different device if possible. If you opened an attachment, disconnect from the network and run a full security scan. Then report the email as phishing in your mail app: one report trains the filter that protects thousands of other people.
Phishing is not a technical attack. It is a psychological one delivered over a technical channel. The email does not break anything; it persuades you to break it yourself. Understanding the persuasion is far more useful than memorising a list of suspicious words.
Nearly every phishing message runs the same four-part script:
When you feel that particular jolt of alarm reading a message, that feeling is the attack. It is manufactured. Treat it as the signal to slow down rather than to act.
The display name is free text and can say anything. "New Zealand Post" as a name means nothing. Expand the actual address. Look for lookalike domains, extra words, and public mail services — a genuine bank does not email you from a gmail.com address.
"Dear Customer" or "Dear user" from an organisation that knows your name is a warning. Bulk phishing goes out to millions and rarely personalises. Be aware, though, that targeted attacks do use your real name, often taken from a previous breach, so a correct name is not reassurance.
Hover over links on a computer, or press and hold on a phone, to see where they actually go. Compare against the domain the organisation really uses. Our link safety checker explains how to read one correctly.
Unexpected attachments are the highest-risk element in any email. Be especially wary of documents that ask you to enable editing or enable content, of archive files, and of anything claiming to be an invoice you were not expecting.
Legitimate organisations do not ask by email for your password, full card number, PIN, or a two-factor code. Nor do they ask you to move money to a "safe account", which is not a thing that exists. Any of these means the message is fraudulent, no matter how convincing it looks.
The classic advice about typos and clumsy grammar is now close to useless. Generative writing tools have made fluent, correctly punctuated, contextually appropriate phishing trivial to produce in any language. A message can be flawless and still be fraudulent.
The durable signals are structural rather than stylistic: who is really sending it, where the link really goes, and whether the request itself is something a legitimate organisation would ever make. Those have not changed and will not.
The most expensive version of this attack does not target consumers at all. An attacker gets into a real mailbox, reads the conversation history, waits for an invoice to be discussed, then replies in the existing thread with updated bank details. There is no suspicious sender, no odd link, no attachment, and the writing style matches because it is the same account.
The only reliable defence is process: verify any change of payment details by phoning a number you already had on file, never a number in the email. This single rule prevents the large majority of these losses.
Not reliably. Modern phishing is often perfectly written, in any language. Judge the sender address, the link destination and the nature of the request instead of the writing quality.
Opening a message is generally safe on a modern, updated mail client. The risk comes from clicking links, opening attachments, or replying. Avoid loading remote images, which can confirm to the sender that your address is active.
Not necessarily. Personal details are widely available from previous data breaches, and attackers use them precisely because they make a message convincing. Verify through the company's official app or a phone number you look up yourself.
You are most likely fine. Close the page, and keep your browser and operating system updated. If you are unsure whether something downloaded, run a full antivirus scan.
Change it immediately, starting with that account and then anywhere else the same password was used. Turn on two-factor authentication. Check your email settings for forwarding rules or recovery addresses you did not add, because attackers often plant those first.