Email Scam Checker Email Scam Checker

Email Scam Checker FAQ

Wondering whether an email is legit? These are the questions people ask before and after installing Email Scam Checker - which providers it works with, whether your email content ever leaves your browser, and how the on-device AI reaches a verdict. Every answer is rendered from the same documentation the extension ships with. If you want the manual checklist instead, see how to spot a phishing email.

Email Scam Checker FAQ

What Email Scam Checker is

Wondering whether an email is legit? Email Scam Checker scores every message you open and shows the verdict next to it in your inbox. These are the basics.

It automatically scans every email you open in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, or Zoho Mail and flags potential scam and phishing emails. A colored badge appears on each email showing whether it looks safe, suspicious, or like a scam.

The extension runs multiple heuristic checks on each email β€” it looks for sender impersonation, suspicious domains, link mismatches, urgency language, generic greetings, dangerous attachments, and other phishing patterns. Nearly all checks happen locally in your browser; only four lookups reach the network β€” a domain registration-date check that sends the bare domain name to the registry serving its domain ending (after a fetch of the public registry list, which contains nothing about you), resolving a shortened link to see where it points, fetching an image to decode a QR code hidden in it, and a lookup of your own scan history to see how many times that domain has been scanned.

Gmail (mail.google.com), Outlook (outlook.live.com and outlook.office.com), Yahoo Mail (mail.yahoo.com), Proton Mail (mail.proton.me), iCloud Mail (www.icloud.com/mail), and Zoho Mail (mail.zoho.com and regional domains such as mail.zoho.eu).

Green (🟒) = the email looks safe. Yellow (🟑) = the email has some suspicious patterns. Red (πŸ”΄) = the email looks like a scam. Click the badge to see exactly what was found.

No. The extension runs quickly on each email and caches results so it doesn't re-scan emails you've already checked.

You can turn email scanning off at any time from the popup: toggle "Email scanning" to OFF to stop checking emails, and back ON to resume. The change applies immediately to the email you're currently viewing.

Privacy: what leaves your browser

Nearly all scam detection happens in your browser β€” no email content is ever sent anywhere to be analyzed. Four lookups do reach the network, and each sends only what it needs: to check how recently a link's domain was registered, the extension looks up which registry serves that domain ending in the public list of registries (a fetch that carries nothing about you or the email), then sends the bare domain name (for example, paypal.com) to that registry; to see where a shortened link (like bit.ly/…) really points, it asks the shortener service with a request that doesn't follow the link or download anything β€” the same thing that happens when you click a link yourself; to decode a QR code hidden in an image, it fetches that image and decodes it on your device; and it queries your own scan history to see how many times that domain has been scanned. The full email body, the complete list of links in a message, and any attachments are never sent. Separately, to keep your personal stats dashboard and recent-scams list working even after a fresh browser profile, a short summary of each scam email β€” the sender, subject, verdict, the quoted fragments that triggered any finding, and the phrases you recorded when a labelled anti-phishing code appears β€” all of them if it does not match, and the matched one if it does, never the full body β€” is backed up to a private store tied to your installation only.

No. Your scan history is private to your own installation. It's tied to a unique, anonymous identity created for this installation β€” no other installation, including other users of the extension, can read it.

Resolving a shortened link means asking the shortener service (like bit.ly) where the link points. The extension sends only the short URL itself β€” which is already in the email β€” using a lightweight request that doesn't follow the link, download anything, or send any of your email content or cookies. This is essentially the same thing that happens if you were to click the link yourself.

The codes are stored in your browser's local storage, and they are never sent to the shortener, the domain registry, or any other third party. They do leave your browser in one case: when a scanned email shows a labelled anti-phishing code. A mismatch puts every phrase you have configured, for every service, into the summary of that scan; a match puts the matched phrase into it. That summary is backed up to a private store tied to your installation only. Nothing else about them leaves your browser.

When the extension gets it wrong

Click the badge and then click "Mark as safe". The sender will be added to your personal safe list and won't be flagged again. You can also review the detailed findings to see exactly what triggered the flag. You can view, rename, or remove safe-marked senders later from the extension popup's Settings screen. If instead you click "Report scam", the sender is saved to a separate "Reported as scam" list for your own reference β€” it doesn't change how future emails from them are scored.

Open the popup, click the gear icon for Settings, and scroll to the "βœ“ Marked as safe" and "βš‘ Reported as scam" sections. Each lists the senders you've acted on, with the service name and email address.

Yes. Click "Edit" on any entry to rename the service label, or click "βœ•" to remove it. Removing a sender from the safe list means the extension will start flagging their emails again if warranted.

No β€” the extension never auto-blocks a sender. Reporting adds them to your "Reported as scam" list, and it counts the email you reported toward your scam statistics and recent-scams list, which is useful when the extension scored something as merely suspicious and you know it was a scam. It doesn't change how the extension scores their *future* emails.

How email checks work

The checks catch 80–90% of common mass phishing emails β€” the kind that make up the vast majority of threats in most inboxes. Phishing emails are templated and predictable, and these 28 checks target their most common patterns, including domain lookalikes, credential-harvesting language, manipulation tactics, and financial scam wording. For sophisticated spear-phishing, use the AI Deep Scan for a second opinion.

Currently, all 28 checks run automatically. The on/off toggle in the popup controls the entire extension.

Phishing sites are disposable β€” scammers register a domain, use it for a few days, then move on. Legitimate companies and organizations almost never send email linking to a domain they registered in the last month. So when the extension sees a link (or a sender) on a domain registered less than 30 days ago, it flags it as a strong warning sign. This catches scams that use an ordinary-looking new .com or .net address, which a list of suspicious domain endings alone would miss.

The registration date comes from the registry that serves the domain's ending. Some endings have no publicly available registry to ask β€” .ru and .Ρ€Ρ„ are among them β€” and a domain whose age can't be determined is never flagged for being new.

A shortened link hides where it really leads, so it's flagged as a caution on its own. The extension also resolves it to its real destination β€” a moment after the email first appears β€” and checks that destination the same way it checks any other link. If it points at a suspicious site (a lookalike domain, a newly-registered domain, a risky domain ending), the warning appears at the real target. If it just points at a site you'd otherwise trust, it isn't treated as suspicious for having been shortened.

Companies often route links through a click-tracking wrapper β€” Microsoft's "Safelinks", Google's /url, Yahoo's link shim, or a bulk-email service β€” before the link reaches you. The visible address is the wrapper's, but the real destination is tucked inside it. The extension unwraps the known wrappers and checks the *real* destination instead, so a legitimate tracked link to a real site no longer shows a "redirect" warning. If the hidden destination is itself suspicious (a lookalike domain, a raw IP address, a risky domain ending), the warning still appears β€” just pointed at the right target.

Two ways attackers register a fake domain that looks like a real brand's domain. A homoglyph domain swaps in a look-alike character from another alphabet (a Cyrillic "Π°" instead of a Latin "a") so the domain looks identical at a glance. A typosquatted domain is a near-miss misspelling β€” one or two characters changed, added, or removed, like "paypa1.com" instead of "paypal.com". The extension checks both sender addresses and link destinations for these patterns, and also checks the subject line itself for the same look-alike-character trick (e.g. a Cyrillic "А" standing in for a Latin "A" in "Аmazon order confirmation").

A classic trick: the email appears to come from "support@yourbank.com", but if you hit reply, your response actually goes to a completely different, unrelated address. The extension checks for this when the mail provider shows the Reply-To address on screen. This is currently most reliable on Gmail; other providers may not show enough information for this check to catch every case.

"Kindly" is one of the strongest linguistic signals of scam emails originating from India and Nigeria. It almost never appears in legitimate English business communication from US or European companies. The check has a specific exception: if the sender is warning you about phishing (like "Kindly note: Please be aware of phishing sites"), it won't be flagged.

The checks are primarily designed for English-language emails. Domain- and link-based checks (sender mismatch, suspicious domains, homoglyph/typosquat domains, link mismatch, link destinations, generic action-link mismatch) work regardless of language.

Among the language-specific checks, the highest-value ones also recognize common Russian-language scam phrasing: urgency language, credential-harvesting requests, gift-card/financial-scam wording, the "kindly"-style overly formal request pattern, and the authority/fear manipulation patterns. There's also a dedicated check for Russian government-inspection scams β€” emails claiming an unscheduled inspection, a received complaint, or an administrative fine from a body like Π ΠΎΡΡΠ΅Π»ΡŒΡ…ΠΎΠ·Π½Π°Π΄Π·ΠΎΡ€ or ЀНБ. Other language-specific checks (grammar errors, generic greetings, and the reward/CEO-impersonation manipulation patterns) are still English-only. Other languages beyond English and Russian aren't yet covered by the wording-based checks.

QR codes and quishing

Quishing hides a malicious link inside a QR code, so the destination stays invisible until you scan. It is the one check that makes this extension different, so it gets its own section. Read the full guide to quishing.

Yes. If an email embeds a QR code that decodes to a web address, that address is run through the same link checks as any other link (suspicious domains, redirect shorteners, homoglyphs, and so on), and the presence of a QR code itself is flagged as a low-severity caution. This catches "quishing" β€” the trick of hiding a link's real destination inside a QR code so neither you nor a plain URL filter can see where it goes until you scan it.

The scanner also looks inside attached files β€” PDFs, standalone images (.png, .jpg/.jpeg, .gif, .webp, .bmp), and Office documents (.docx, .xlsx, .pptx). A QR code hidden inside one of these (or, in an Office file, a clickable link tucked into the document) is decoded and checked the same way. This works across the supported mail providers. Proton Mail's attachments are end-to-end encrypted, so their file contents can't be read directly β€” the one exception is an image attachment you open in a preview, which the extension decodes. Anything the extension still can't read falls back to the lower-severity "attachment may hide a link" caution.

QR codes shown as images are also scanned even when the image itself is hosted on a remote server (rather than embedded directly in the email) β€” the extension fetches and decodes those in the background. This result appears a moment after the initial verdict, the same way the freshly-registered-domain check does.

AI Deep Scan

AI Deep Scan is an optional second-opinion analysis powered by an on-device phishing detection model (DistilBERT). The model downloads once (~67 MB) and then runs entirely offline in your browser. It provides its own verdict, confidence percentage, and detailed reasoning. No email content is sent to a server for this analysis.

No. The AI model downloads automatically the first time you use Deep Scan. No separate installation or configuration needed.

About 67 MB. It downloads once and is cached in your browser permanently.

Yes β€” after the first download. The model is stored in your browser's cache and runs entirely offline after that.

After the model is cached, analysis takes a few seconds. Without cache (first use), the download takes 10–30 seconds depending on your internet connection, then analysis is near-instant.

The automatic heuristic checks look for specific, known patterns β€” like sender impersonation, suspicious links, or urgency language. The AI model has been trained on thousands of real phishing emails and can detect more subtle patterns that rule-based checks might miss.

Both approaches have strengths. Heuristic checks catch 80–90% of common mass phishing instantly. The AI model can catch more sophisticated attacks but takes a few seconds to run. Using both gives you the best coverage β€” automatic heuristics for speed, AI for a second opinion.

"Trust" is the wrong frame for it β€” it's a second opinion, not a verdict. Its published benchmark score is 99.58%, but that benchmark is mostly URL samples rather than emails, so we don't quote it as an email-accuracy figure. On that benchmark's email samples we measured it catching roughly 99% of phishing and flagging about 3% of legitimate mail, and those are benchmark emails, not your inbox. No automated system is perfect β€” always use your own judgment. The AI's reasoning text helps you understand why it reacted the way it did; it isn't proof.

No. Heuristic checks run automatically. AI Deep Scan is manual β€” you choose when to run it by clicking the button in the scam indicator popover. This keeps the extension fast and gives you control over when to use the more resource-intensive AI analysis.

If the AI says an email is safe but the automatic heuristic checks found strong warning signs, the result won't simply show "safe" β€” you'll see a warning explaining that the AI and the heuristics disagree, and the overall result leans toward the more cautious, heuristic-backed reading. The AI can never single-handedly clear an email that the heuristics have flagged with strong evidence.

The reverse also happens: the AI can see phishing patterns in an email that no heuristic check found anything wrong with. Because the model isn't calibrated for this β€” it also flags ordinary receipts, statements, and delivery notices β€” that case gets its own note telling you the finding is a hint rather than a verdict, and pointing you back to the heuristic result. The AI's own verdict is never shown as authoritative.

Anti-Phishing Codes

It's a personal secret phrase that some services include in every email they send you. If an email claims to be from that service but your code is missing or wrong, it's a scam. Think of it as a password that proves the email is really from who it claims to be.

Open the extension popup, scroll to the Anti-Phishing Codes section, and click "+ Add another service". Enter the service name (for example, "Gate" or "Binance") and your personal code for that service. You can add as many services as you need.

Proton Mail, Gate, Binance, Coinbase, and several other crypto exchanges and email providers include anti-phishing codes in their emails. You can use this feature with any service that includes a consistent personal phrase in their emails.

As many as you need. Each service gets its own entry with a label and code. You can add, edit, or remove codes anytime from the extension popup.

Edit the code in the extension popup to match. Click "Edit" on the service row, update the code, and click "Save". If you don't update it, the extension will flag matching emails as a mismatch (critical scam signal) until you do.

No. The extension only checks the text immediately after the anti-phishing label (within ~200 characters, up to the next paragraph break). A code configured for Gate won't accidentally match a Coinbase email just because it appears in a footer or boilerplate elsewhere in the body. Each code is verified only against the text near its own label.

They're optional but highly recommended if you use any service that includes them. An anti-phishing code mismatch is one of the strongest possible scam signals β€” scammers can fake a lot of things, but they can't know your personal secret phrase.

First-time senders

An email from a sender domain the extension has never seen in your scan history before. It means you have not previously opened an email from that domain while the extension was running.

A legitimate company you already deal with will normally be in your history. A brand-new domain is a common pattern in spoofing and business-email-compromise scams β€” a fake invoice, a "please update your payment details" request, or an "are you available?" message from someone pretending to be a colleague you've never actually corresponded with.

No. It adds a medium-level caution (+10 points), not a scam verdict. A lone first-time sender still reads "safe" β€” you just see a note that it's the first time you've heard from that domain. Only if another warning sign appears does the email tip to "suspicious".

No. Free-email domains like Gmail, Yahoo, Outlook, and Proton Mail are excluded β€” they're shared by millions of unrelated people, so "first email from gmail.com" would be meaningless noise rather than a real warning sign. The flag only applies to a company's own domain (like gate.com or yourbank.com).

No β€” the history only starts when the extension is installed. The first time you open an email from a company you've known for years, it may be flagged as a first-time sender because the extension has never seen that domain before. After that first scan, the domain is in your history and won't be flagged again.

Your scan history is backed up to a private store tied to your installation, so it can survive a browser-data clear on the same installation. It does not follow you to a different computer (each installation has its own history).

Trusted contacts

A sender domain you've received several emails from (three or more) while the extension has been running. It's a domain you correspond with regularly, so the extension treats it as a mild vote of confidence.

A legitimate but low-volume sender β€” a small vendor, a freelancer, a niche service you actually use β€” can occasionally trip a heuristic check on wording or link formatting. If you've clearly had a long-running relationship with that domain, the extension softens the score a little to reduce false positives, without ignoring real warning signs.

No. It lowers the risk score by 10 points. A clean email reads safe either way; a borderline email is more likely to land on "safe" instead of "suspicious"; but an email with a serious red flag β€” a suspicious link, a mismatched reply-to, an urgent demand β€” is still flagged regardless of how often you've heard from the domain.

Three. Once the extension has scanned at least three distinct emails from the domain, it's a trusted contact. One or two emails is the neutral zone β€” no signal either way.

The domain. A company's From-addresses rotate (billing@, noreply@, updates@), but the domain stays stable. Subdomains are collapsed too, so notifications.hubspot.com and hubspot.com count as the same sender.

No. Free-email domains like Gmail, Yahoo, Outlook, and Proton Mail are excluded. Bulk-email platforms like SendGrid, HubSpot, and Mailchimp are excluded too β€” those domains are shared by many unrelated senders, so "trust" must apply only to a company's own domain.

The extension simply skips the trust signal β€” it never lowers a score it couldn't verify. Your scan still completes normally.