In short
Every email you open gets 28 rule-based checks, a score built from what they find, and a colored badge: green for safe, yellow for suspicious, red for a likely scam. The scan runs in the browser you already have open, so the verdict is waiting as you read.
- 28 checks run locally on every email - sender, links, language, and attachments.
- Each finding adds points; the total decides Safe, Suspicious, or Scam.
- Nothing to configure, and the verdict is computed on your device.
How a scan runs
There is nothing to switch on. The moment you open a message, the extension reads the parts of it you can see - the sender's display name and address, the subject line, the body text, every link and the address it really points to, and the names of any attachments. On an encrypted provider such as Proton Mail, that reading happens only after the provider has decrypted and displayed the message locally. The text then goes through the 28 checks, each looking for one pattern, and their points add up into a single risk score that colors the badge on the message.
The 28 checks
Each check asks one narrow question. Here is what the 28 are watching for, grouped by what they look at.
Checks that look at the sender
A phisher's first job is to look like someone you trust, so several checks compare the identity an email claims with the one it was sent from. Sender mismatch catches a display name that reads like a company ("PayPal Support") while nothing in the address matches it, ignoring generic role words so ordinary service mail is left alone. Suspicious domain flags a brand name inside a domain that is not the brand's own, or a known company writing from a free mailbox. Display-name brand impersonation narrows that to a brand followed only by generic words ("Coinbase Support") from an unrelated domain, skipping businesses whose own domain contains the word. Typosquatting finds near-miss misspellings like "paypa1.com"; homoglyph detection catches look-alike characters from another alphabet - a Cyrillic "а" for a Latin "a" - in the domain and the subject line. Two more sit here: one flags an email that mentions a known brand throughout while coming from an unrelated domain, ignoring social platforms like X or Discord, and Reply-To mismatch catches an email whose replies would go elsewhere entirely.
Checks that look at links
The second group asks where the email wants to send you. Link mismatch catches link text naming a trusted site while the address behind it goes elsewhere. Redirect links flags URL shorteners such as bit.ly and t.co, then resolves them so the real destination can be checked too. QR-code links catches the same idea in a QR code - the "quishing" trick, decoded here from the message, from a remotely hosted image, or from inside an attached PDF, image, or Office document. Suspicious link destinations marks raw IP addresses and the domain endings phishing overuses, such as .xyz and .top. Brand hidden in a subdomain catches "paypal.com.phishing.xyz", a real brand embedded in an unrelated domain. Generic action-link mismatch covers the most common phishing link of all: a button labeled "Click here" or "Verify now" pointing off the sender's own domain, though not on personal mailboxes. Link density and link domain diversity flag mail that is mostly links, or that scatters them across unrelated domains. Hidden links flags a clickable link concealed with CSS; alone it is weak, since legitimate mail hides links for layouts and collapsed replies.
Checks that look at the writing
The third group reads the words. Urgency language catches pressure phrases such as "your account has been suspended" or "verify within 24 hours"; strong ones fire at once, weaker ones need repetition. Credential-harvesting language catches the ask that usually follows ("sign in to verify your account"), which real companies do not make by email. Generic greeting flags "Dear user" where a correspondent would use your name, and grammar errors picks up the mistakes common in scam templates. "Kindly" phrasing counts because the word almost never appears in genuine business mail, except when a sender is warning you about phishing. Psychological manipulation looks for authority pressure, threats, "you have won" bait, and CEO-impersonation wording, while financial scam patterns covers gift-card requests, wire transfers, invoice fraud, inheritance offers, and sextortion. Government-inspection scams get their own check - a claimed inspection, complaint, or administrative fine from a body like Rosselkhoznadzor or the FNS, with the real link or QR code in an attachment - critical when the message comes from a free mailbox. Hidden content catches scam wording concealed with CSS but absent from the visible message, and anti-phishing code mismatch compares a code label against the codes you configured: the one check that rests on the sender knowing a shared secret.
Checks that look at attachments
Suspicious attachments catches executables dressed as documents - .exe, .scr, or .js files, including double extensions like "invoice.pdf.exe" where a document extension hides the real one. Attachment may hide a link or QR code flags an email carrying an attachment and no visible links in the body, which is how a scam keeps its destination off screen. For PDFs, images, and Office files the extension opens the file and decodes any QR code inside, and in an Office document it also reads the ordinary hyperlinks tucked into it; the check is the fallback for what cannot be read, such as an SVG, a legacy .doc, or an encrypted Proton Mail document.
How the score becomes a verdict
The checks do not vote; they add up. Every finding carries a severity and every severity a number: low is 5 points, medium 10, high 20, critical 50. The total decides the verdict. Below 20 the email is Safe; from 20 to 49 it is Suspicious, warning signs but no conclusion; at 50 or above, or the moment a single critical finding fires, it is Scam. The thresholds assume the two mistakes cost differently: a missed scam can cost an account, a false alarm a moment. Positive signals push the other way - an unsubscribe link, a postal address, and links that point consistently back to the sender's own site subtract points, and mail genuinely sent through a bulk platform has its urgency wording downgraded. Those credits have a floor: credential-harvesting language keeps an email at least Suspicious however many good signals surround it.
Links, shorteners, and tracking wrappers
Legitimate companies rarely send their bare links. A real newsletter often arrives with every URL wrapped in a click-tracking redirect - Microsoft's Safelinks, Google's /url, Yahoo's link shim, or a bulk-email tracking domain - so the address behind the link is not the site you are being sent to. The extension unwraps the wrappers it knows and runs the link checks against the real destination, so a tracked link to a site you would otherwise trust is not flagged merely for being tracked; a wrapper hiding a suspicious destination is still caught. Shorteners get the same treatment plus a step: a bit.ly address is flagged as a caution on its own, then resolved so its destination is checked like any other link. The rule punishes concealment, not convenience.
What you see when you click the badge
The badge is the summary; the popover behind it is the evidence. Click the badge and you get every finding that fired, each explained in plain language and each showing the exact text, link, or header value that triggered it, so a verdict never arrives without its reasons. "Mark as safe" and "Report scam" sit in the same place. The popup keeps the running tally - emails checked today and how many were scams, the same totals all time, and the most recent scams by sender and subject.
Where the checks run
All of it runs in the browser you already have open: the analysis happens locally, on the message you are viewing, and the verdict never waits on the network. The same engine and the same 28 checks run on Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail; only how the extension reads the page differs. A few lookups do reach the network, and each sends only what it needs: a bare domain name to the public registry for its registration date, the shortened URL itself to the shortener to learn where it points, a fetch of a remotely hosted image so its QR code can be decoded, and a query against your own scan history to see whether you have received mail from that sender's domain before. To keep that history and your statistics working after a cleared browser or a new machine, a short record of each email the extension scans - sender, subject, verdict, the quoted fragments that triggered any finding, and the phrases you recorded when a labelled anti-phishing code appears - all of them if it does not match, and the matched one if it does, never the full body - is stored in a private place tied to your installation, where it is not visible to anyone else.
Final verdict
Heuristic scanning is not clever. It is 28 narrow questions asked of every email you open, each one scored, all of them added into a verdict you can act on in a second. That keeps it fast, free and predictable, and it is why these rules catch the great majority of common mass phishing - templated, repetitive mail they know well. What they cannot do is judge a well-written, targeted message that breaks no rule at all; that is what the on-device AI deep scan is for. Open an email and the badge, the score, and the reasons are already there.
For the full walkthrough of every check, see how Email Scam Checker works. For the reader's side of the same red flags, see how to spot a phishing email.