Email Scam Checker catches phishing and scam emails by running 28 on-device heuristic checks against every message you open, turning each finding into a risk score, and - when you want a second opinion - a DistilBERT AI model that runs entirely in your browser. Every email gets a colored badge: green for safe, yellow for suspicious, red for a likely scam. Click the badge and you see exactly what triggered it, in plain language.
- We run 28 independent checks on every email - sender, links, language, and attachments - not a handful.
- Each finding is weighted by severity (5, 10, 20, or 50 points) and combined into a single 0-100 risk score.
- The whole analysis runs in your browser. A few lookups do reach the network, and each sends only what it needs: a bare domain name to the public registry, the shortened URL to the shortener, a remotely hosted image fetched to decode its QR code, and a query against your own scan history. A short summary of each scam is also backed up to a private store tied only to your installation - sender, subject, verdict, the quoted fragments that triggered any finding, and the phrases you recorded when a labelled anti-phishing code appears - all of them if it does not match, and the matched one if it does, never the full body.
- An optional AI deep scan (DistilBERT, about 67 MB) gives a second opinion, entirely offline after a one-time download.
- Anti-phishing codes let you prove an email really came from Proton Mail, Coinbase, Gate, or Binance.
What Email Scam Checker is
Email Scam Checker is a Chrome extension we built to catch phishing and scam emails automatically, in the inbox you already use. It works by running heuristic checks - rule-based tests that each look at one narrow aspect of an email for a pattern we have seen in real scams. One check compares the display name to the actual sending domain. Another looks for urgency language. Another decodes QR codes. Together, 28 of these checks cover the ways phishers actually trick people, and our guide to spotting a phishing email walks through the same red flags from the reader's side.
I built this extension because the gap between what most people can spot and what a well-crafted phish actually looks like is where every successful scam lives. The checks below are not generic security advice - they are the literal logic the extension runs, and each one exists because it reflects a real phishing or scam pattern we have observed or documented.
Why a checklist is not enough
The classic advice is to check the sender, hover over links, and watch for urgency. That catches an obvious phish, but a skilled one sails past a quick read - a lookalike domain, a shortened link, a QR code, or a message sent from a compromised real account. Phishing is social engineering, not a technical exploit: it targets your attention and your willingness to act, and nobody has time to run a full checklist on every single message. Business email compromise - where a scammer poses as a colleague or vendor to request a wire transfer - often carries no malicious link at all, which is part of why the FBI's Internet Crime Complaint Center reports it among the costliest scam categories year after year.
There is also a category of tools that show up when people search for an "email scam checker" that do something different from us: they verify that an email address exists, or check a domain's deliverability. That is a useful job for a marketer, but it does nothing to stop you from clicking a malicious link. We do the other thing - we detect phishing content inside the email itself. Different problem, different answer.
The 28 heuristic checks, explained
When you open an email, we extract the sender, subject, body text, links, and any visible attachment names, then run 28 independent checks against them. I have grouped them by what each one looks at, so you can see the logic without reading 28 separate rules.
Sender and domain checks
The first thing a phisher fakes is the sender, so the first group of checks attacks the domain. Sender mismatch catches a display name that looks like a company ("PayPal Support") while the underlying address has nothing to do with it. Suspicious domain flags a brand name used inside a domain that is not the brand's own, like "paypal-secure-alert.com". Display-name brand impersonation catches a name that opens with a known brand ("Coinbase Support") sent from an unrelated domain. Typosquatting finds near-miss misspellings like "paypa1.com", and homoglyph detection catches the sneakier version - a Cyrillic "а" swapped in for a Latin "a" so the domain looks right at a glance. We check the subject line for the same lookalike-character trick, because that is where it is easiest to slip past a quick read.
Link checks
The second group attacks where the email wants to send you. A phishing link is one whose real destination is hidden or faked - the text shows one address while the link actually leads somewhere else. Link mismatch catches visible text that claims one destination while the link goes elsewhere. Suspicious link destinations flags raw IP addresses and domain endings that are overrepresented in abuse, like .xyz or .top - treated as a supporting signal, never proof on its own. Brand hidden in a subdomain catches "paypal.com.phishing.xyz". Redirect links flags URL shorteners and click-tracking wrappers (more on how we unwrap those below). QR-code links flags any QR code that decodes to a web address - the "quishing" trick. Reply-To mismatch catches an email that appears to come from one address while replies actually go somewhere unrelated, and generic action-link mismatch catches one of the most common phishing-link patterns we see: a "Verify Now" or "Click Here" button that points off the sender's own domain. Link density and link domain diversity flag emails that are mostly links, or that scatter links across many unrelated domains - both unusual for legitimate mail.
Language and psychology checks
Phishing works because it manipulates you, so the third group reads the words. Urgency language catches "your account has been suspended" and "within 24 hours". Credential harvesting catches "sign in to verify your identity". Generic greeting flags "Dear Customer" instead of your name, and grammar errors flag the writing mistakes that cluster in scam templates. "Kindly" phrasing can contribute a weak language-risk signal when it appears alongside financial, urgency, or impersonation indicators - the wording alone never determines the verdict. Financial scam patterns catch gift-card requests, inheritance bait, invoice fraud, and sextortion language, while psychological manipulation catches authority pressure and "you have won" reward bait. There is even a check for government-inspection scams - emails claiming an unscheduled inspection or an administrative fine from a body like Rosselkhoznadzor or the FNS, the kind of message that arrives from a free consumer-mail address, which would be highly unusual for an official regulator notice.
Attachment and hidden-content checks
The last group covers what you cannot see on the screen. Suspicious attachments catches executables disguised as documents, including double extensions like "invoice.pdf.exe". Hidden content catches scam phrasing tucked into invisible or zero-size text with CSS - shown to a scanner but not to you. And attachment may hide a link or QR code flags the shape of an email where the real link is buried inside an attached document instead of printed on screen.
From findings to a verdict - how the risk score works
Each check that fires adds points to a risk score based on how serious it is. This is what turns 28 individual observations into one verdict you can act on.
| Severity | Points | Example |
|---|---|---|
| Low | 5 | A shortened link that resolves to a trusted site |
| Medium | 10 | A first-time sender domain with no history |
| High | 20 | A typosquatted or homoglyph domain |
| Critical | 50 | An anti-phishing code that does not match |
The total maps to three verdicts. Below 20 is Safe - no significant warning signs. Between 20 and 49 is Suspicious - some signals, but not definitive. Fifty or above - or any single critical trigger - is Scam. Positive signals work in the opposite direction: an unsubscribe link, a physical address, or links that consistently point back to the sender's own site subtract points as weak contextual signals, while a matching anti-phishing code is a far stronger authenticity signal - so a legitimate marketing email with a bit of urgency language is not falsely condemned. But a serious red flag, like credential-harvesting language, is capped so that positive signals cannot erase it entirely without stronger verification - they soften a borderline case, never clear a dangerous one.
One more check runs on top of the 28 local heuristic checks - a single network-assisted domain-age lookup. If an email links to - or comes from - a domain registered in the last 30 days, we flag it as a warning sign. Recently registered domains are disproportionately useful to attackers, so we treat domain age as a supporting risk signal rather than proof. This lookup sends only the bare domain name to the public domain registry - never your email content or the full link - and its result appears a moment after the rest.
Reading the links you can't see
Two of the most useful checks are worth a closer look, because they handle the cases where the real destination is hidden from you on purpose.
Companies often route links through a click-tracking wrapper before they reach you - Microsoft's Safelinks, Google's /url, Yahoo's link shim, or a bulk-email service. The visible address is the wrapper's, and the real destination is tucked inside. We unwrap the known wrappers and check the real destination instead, so a legitimate tracked link is not falsely flagged while a wrapper hiding a suspicious site still is. Shortened links work the same way: a bit.ly or t.co address is flagged as a caution on its own, then resolved to its real destination a moment later, and that destination is checked like any other link. Resolving a short URL requires contacting the shortener or following its redirect chain, but the lookup carries no email body or message metadata.
QR codes are where this gets genuinely hard to spot, because the destination stays invisible until the code is scanned - the attack we cover in depth in our guide to quishing. We decode QR codes wherever they hide: embedded in the email, tucked inside an attached PDF, image, or Office document, or even served as a remote-hosted image rather than a file attached to the message. Any web address found inside a QR code runs through the same link checks as an ordinary link. Proton Mail's attachments are end-to-end encrypted, so their contents cannot be read directly - the one exception is an image attachment you open in a preview, which we decode.
Sender history - first-time senders and trusted contacts
The extension also learns from your own inbox, and that history is one of the few things that reaches the network: the sender's domain is checked against it to see whether you have received mail from that domain before. We keep a history of every domain you have received mail from, and use it to tune the score in two ways. A domain you have never seen before gets a first-time sender caution worth 10 points - enough to tip a clean-looking message to Suspicious the moment any other signal appears, and a useful guard against spoofed invoices and business-email-compromise probes. The inverse is a trusted contact: a domain you have received mail from three or more times gets a 10-point positive signal, cutting down on false positives for the senders you actually deal with. Matching is by domain, not full address, so a company's rotating "billing@" and "noreply@" addresses count as the same sender - and free-email domains like Gmail are excluded from both signals, since a random personal address carries no meaningful history.
Anti-phishing codes - proving a sender is who they claim
Some services give you a way to verify an email that no attacker can fake: a personal secret phrase they include in every legitimate message. Proton Mail, Coinbase, Gate, and Binance all do this. You configure your code in the extension popup, and from then on, any email that claims to be from that service is checked against it. If the label is there and the code matches, you get a green confirmation - a strong authenticity signal that the message matches what you configured for that provider. If it does not match, that is a critical trigger worth 50 points, because a scammer who does not know your secret phrase cannot get it right. Your codes are stored in your browser and compared there. They leave it in one case: when a scanned email shows a labelled anti-phishing code, the phrases you recorded are written to that email's scan record, a private record tied to your installation. A mismatch writes all of them, for every service; a match writes the matched one.
AI Deep Scan - the on-device second opinion
The heuristic checks are fast and catch many common, rule-detectable phishing patterns instantly. AI-written phishing is harder to catch, because it drops the grammar errors and urgency tells the rules rely on. For the harder cases - a targeted spear-phish that does not trip any single rule - we added a second layer: a DistilBERT phishing model running entirely in your browser. Its published benchmark score is 99.58%, but that benchmark is mostly URL samples rather than emails; on that benchmark's email samples we measured roughly 99% of phishing caught and about 3% of legitimate mail flagged. The full write-up of how that model is measured covers the benchmark split, the false-positive rate with its confidence interval, and what we still cannot measure. You trigger it by clicking "Deep Scan with on-device AI" on an email's badge; the model downloads once (about 67 MB), then runs offline via WebAssembly, and returns its own verdict, a score, and a short plain-language explanation.
| Signal | Heuristic checks | AI Deep Scan |
|---|---|---|
| How it works | 28 rule-based tests for known patterns | A DistilBERT model trained on real phishing emails |
| When it runs | Automatically, on every email | On demand, when you click the button |
| Strength | Instant, catches many common rule-detectable patterns | Catches subtler, targeted attacks rules miss |
| Network | Local (one bare-domain lookup excepted) | Fully offline after a one-time download |
The two layers do not just sit side by side - they are fused. The AI also sees what the heuristic checks already found, so it can factor in a suspicious sender domain a text-only model might miss. And the fusion rule is deliberately cautious: strong heuristic findings cannot be waved away by an AI verdict of "safe", while the AI alone can raise a verdict to Suspicious but never all the way to Scam without the heuristics agreeing. When the two disagree, you see a note explaining the disagreement and recommending you trust the heuristic-backed reading - the AI is trained mostly on consumer phishing and can miss more targeted business-impersonation attacks. There is a full breakdown of the trade-off in our comparison of on-device versus cloud AI phishing detection.
The privacy model - the analysis runs in your browser, and the network lookups carry no message body
Everything above runs locally. The heuristics analyze the email text on the page you are already viewing, the AI model runs in WebAssembly, and the QR and attachment decoding all happen in-browser. We built it this way on purpose, because the privacy-conscious users who refuse cloud-based scanners are exactly the people a phishing detector should serve - and because you should never have to trade your inbox for your security.
| Signal | Cloud-based scanner | Email Scam Checker |
|---|---|---|
| Where email is analyzed | On a third-party server | On your device |
| What leaves your device | Email body, sender, subject | A bare domain for age checks, a short URL for resolution, a remotely hosted image for QR decoding, and a scan-history query for the sender's domain. Separately, a private backup of the sender, subject, verdict, the quoted fragments that triggered any finding, and the anti-phishing phrases you recorded whenever a labelled anti-phishing code appears, all of them on a mismatch and the matched one on a match - never the full body |
| Works offline | No | Yes, after the AI model is cached |
A few lookups do reach the network, and each sends only what it needs: a bare domain name to the public registry for its registration date, the shortened URL itself to the shortener to learn where it points, a fetch of a remotely hosted image so its QR code can be decoded, and a query against your own scan history to see whether you have received mail from that sender's domain before. None of them sends the email body, any attachment, or the complete list of links in a message. Separately, to keep your statistics and recent-scams list working if you switch computers or clear your browser data, a short summary of each scam - sender, subject, verdict, the quoted fragments that triggered any finding, and the phrases you recorded when a labelled anti-phishing code appears - all of them if it does not match, and the matched one if it does, never the full body - is backed up to a private store tied only to your installation. It is not shared with, or visible to, anyone else.
Where it works
The extension works across six providers, each with its own integration so the badge appears where you actually read mail: Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail. Because the checks run on the message you are viewing rather than on a copy sent to a server, the same engine and the same 28 checks apply everywhere - including on Proton Mail, where the extension analyzes a message only after Proton Mail has decrypted and rendered it locally in your browser.
What it does not catch
No automated system is perfect, and we would rather be clear about the edges than overpromise. The wording-based checks are built primarily for English, with a subset - urgency, credential-harvesting, financial-scam, and authority/fear patterns - also recognizing common Russian scam phrasing; other languages are not yet covered by the language checks, though the domain and link checks work regardless of language. A genuine email can also trip a false alarm, which is why every verdict comes with a breakdown you can read and a "Mark as safe" button that adds the sender to your personal safe list. And when a message really is a phish, the right next step is to report it - the Recognize and Report Phishing guidance from CISA and the Anti-Phishing Working Group both walk through how, and reporting gives your provider an explicit abuse signal, while simply deleting the message does not.
If you are weighing this against browser-native warnings, antivirus suites, or a manual checklist, our comparison of the best phishing protection lines up what each approach actually catches.
Final verdict - how email scam checker works
Email Scam Checker works by combining 28 on-device heuristic checks with an optional AI deep scan, turning every finding into a weighted risk score and a green, yellow, or red verdict you can act on in a second. The checks cover the sender, the links, the language, and the attachments; the AI catches what the rules miss; and the whole thing runs in your browser, so the extension's network lookups never carry the message body. That is the entire point - protection you do not have to think about, without giving up the inbox you are trying to protect. Install it from the Chrome Web Store and the badge appears on your very next email - there is nothing to configure except the anti-phishing codes you want to verify.