In short
AI Deep Scan is a second opinion you can ask for on any email. It runs a phishing classification model inside your browser and returns its own verdict, a confidence score and a short explanation. Everything else in the extension is automatic; this one waits for you. The button sits in the panel behind the badge, and nothing is classified until you press it.
- An optional DistilBERT model, about 67 MB, downloaded once and cached by your browser. After that it runs offline.
- It returns its own verdict, a confidence score, and two sentences of plain-language reasoning.
- Its result is fused with the rule-based checks rather than shown beside them: a strong finding cannot be talked out of, and the AI on its own cannot reach Scam.
- No API call, no account and no API key: the AI path has no server to send the message to.
Why a second opinion
The 28 heuristic checks are deliberately narrow. Each asks one question with a definite answer: does the display name match the address, does a link's text match where it really goes, does the message use pressure language, does it carry an executable attachment. That narrowness is why they catch the great majority of ordinary phishing instantly. What they cannot do is recognise a message that breaks none of their rules. A scam written for one person, in clean prose, with a plausible story and a domain that has no history of abuse, offers no pattern to match. Nothing was missed; there was nothing there for a rule to find.
A classification model comes at the same question from the other side. It does not look for specific mistakes. It reads the whole message and estimates how much of it resembles the phishing mail it was trained on, which makes it strongest exactly where the rules are weakest. It is also no replacement for them: whether a domain was registered last week, or whether replies would go to an unrelated address, leaves no trace in the writing itself, so a model reading only the message could never establish either. Those facts come from the checks, which is why they are handed to the model as context rather than left to the text. The two answer different questions, which is why the extension runs both and combines them instead of choosing between them. For what the rules cover, see heuristic scanning. For the attacks no text model handles well, see business email compromise detection.
What the model returns
A deep scan ends with four things, shown alongside the heuristic findings.
| What you get | What it means |
|---|---|
| A verdict | Safe, Suspicious or Scam. The model's own reading, before it is combined with the rule-based checks. |
| A confidence score | Zero to 100, drawn as a bar. It is the model's confidence in the verdict it has just given, not a separate risk score. |
| Written reasoning | Two sentences explaining the conclusion in ordinary language, so the verdict never arrives without its reasons. |
| A categorised finding | A labelled line naming the model's estimate of the phishing probability, filed under deception, or under intent when the message reads as legitimate. |
The model's thresholds explain why a Safe from the AI is not the same statement as a Safe from the checks. Above an estimate of 60 percent phishing it calls the message Scam; above 30 percent, Suspicious; below that, Safe. It is a multi-label classifier that scores four categories at once and adds up the ones associated with phishing, which is why the percentage reads directly as a probability.
What it reads is the subject line, the sender line, up to the first 1,500 characters of the body, and a summary of what the heuristic checks already found. The model is told about a freshly registered link domain or a mismatched sender, and asked to weigh them alongside the writing.
On-device, not cloud
The model runs through WebAssembly in your own browser. It is downloaded once, cached by the browser, and loaded from that cache on every later scan. There is no inference API and no account, and the message is not uploaded for classification. Once the model is cached, a deep scan works with the network switched off entirely.
That is the substantive difference from a cloud email security gateway. A cloud gateway is a server in front of your mailbox, and its design requires the message to reach it: to judge an email it must receive it. That data flow is not optional. Running the model on the device inverts that: the text is analysed where it already is.
Two things are worth stating plainly. First, local analysis is not the same as no data anywhere. The extension's other checks still reach the network for a few specific things, which the heuristic scanning page sets out in full, and the extension keeps its usual short record of each email it scans, tied to your installation. The deep scan itself adds nothing to that record, and the AI verdict is not stored at all. Second, the download is one model, not one per mailbox. It is fetched in the background the first time the extension runs on a provider, and the extension remembers that it is available, so your other providers do not start it again.
How the two verdicts combine
The AI does not get a separate opinion column, and the two are never averaged into a number neither of them produced. They are fused, with the rule-based findings taking priority where that is the honest answer.
- A critical finding stands. If a check has already flagged something critical - a link whose text and destination disagree, an anti-phishing code that does not match - the email is a Scam, whatever the model thinks of the writing.
- A high score stands. A rule-based score at or above the scam threshold produces the same result, again regardless of the model.
- The model cannot clear an email. When a check has raised a high-severity warning and the model says the message looks safe, the verdict stays at Suspicious. Safe is the one conclusion the model is not allowed to reach in that situation.
- The model can raise an alarm, not confirm one. If the model calls an email a scam while the checks have found nothing wrong, the verdict moves to Suspicious and stops there. Only the rules can establish a Scam.
- Agreement adds nothing. When the two point the same way, the verdict is simply the verdict, with the model's reasoning underneath it.
There is one disagreement you are told about explicitly, and it is the one that matters. When the model reads an email as safe while a check has raised something serious - a high-severity warning or a critical finding - the panel says so: it names the number of checks that found something, and explains that the model was trained mainly on ordinary consumer phishing and may miss a targeted business impersonation attack, so the checks should be trusted. That is a deliberate refusal to split the difference. In the other direction there is no warning. The fused result follows the rules more closely than that: a model verdict of Scam against clean checks moves the verdict to Suspicious, while a model verdict of Suspicious against clean checks leaves the verdict where they put it, at Safe. The disagreement note is reserved, by design, for the case where the model would otherwise clear an email the checks have flagged.
When to use it
Deep Scan is a second opinion, not a first one, and worth using like one. The heuristic verdict is already on screen when an email is opened, complete with every finding that fired. The deep scan is for the cases where that verdict does not settle the question: a message sitting at Suspicious with a single weak warning behind it, one whose story is plausible but whose tone is slightly off, a request from a supplier or a colleague that reads perfectly normally and still makes you hesitate. On those, a model that reads for intent is a genuinely different voice: it measures the distance between no rule objects and nothing here reads like an attack.
Two cases do not need it. An email the checks have already called a Scam will stay a Scam, because the model cannot lower it, so the click buys only a wait. A message you were never going to act on does not need a formal verdict either. There is a practical cost as well: every scan takes a few seconds of computation, and the first one on a new browser may have to wait for the one-time download. That is why the extension leaves this as a button rather than running it on every message.
Final verdict
AI Deep Scan adds the one thing a rule set cannot supply: a reader. It judges the message as writing rather than as structure, locally on your own machine, and it hands its opinion back into the same verdict the checks produce instead of floating beside it. The design choices point away from overselling it. The model cannot clear a flagged email, cannot reach a scam verdict unaided, and announces the one disagreement in which it might be the one that is wrong. That is a sensible division of labour between a fast, predictable engine and a slower one that understands prose, and why the pairing catches more than either half alone.
For the architecture comparison behind this choice, read on-device vs cloud AI phishing detection.