Email Scam Checker Email Scam Checker

Release notes

Email Scam Checker has grown from a rule-based scanner in two webmail clients into an on-device detector that covers six providers and looks at links, attachments and sender history. Each release below moved it one step along that path.

Read them as the history of a single check. Detection of quishing - a QR code in an image attachment, a PDF or an Office file - arrived in 2.0.3.0. The live domain-age check that flags a newly registered domain came in 2.0.6.0. The on-device AI Deep Scan landed in 2.0.0.0, and the first-time-sender signal aimed at business email compromise in 2.0.2.0.

The list runs newest first, and covers the releases that changed what the extension does - not every build. The extension updates itself through the Chrome Web Store, so you are usually on the latest version without doing anything.

  • 2.0.9.0

    minor

    Deep Scan no longer carries a stale failure into the next email, and the domain-age check now honors its timeout end to end.

    • Deep Scan no longer shows a leftover failure message after you open a different email
    • A failed AI model load is now reported as failed instead of appearing available again
    • The domain-age check's timeout now covers its full lookup, not just the final request
    • Proton Mail's attachment-preview QR check now always matches the email open when it finishes
    Read the full notes
  • 2.0.8.0

    minor

    The domain-registration check now queries the registry that actually serves the domain, and Deep Scan no longer hangs on the first download.

    • The registration-date check now asks the domain's own registry directly, not a shared redirector
    • One fewer third party in the lookup path: only the registry serving the domain's ending is contacted
    • Deep Scan now reports download progress to a scan that starts while the model is already downloading
    • Deep Scan no longer spins forever with no result if you click it during the first download
    • Domain endings with no published registry - .ru and .рф among them - can't be dated, and are never flagged for being new
    Read the full notes
  • 2.0.7.0

    minor

    Reporting a scam now counts toward your statistics, so the counters match what you actually caught.

    • Reporting a sender as a scam now counts that email toward your scam statistics
    • The reported email also appears in your recent-scams list
    • Counted once per email, so reopening and re-reporting can't inflate your numbers
    • Reporting still doesn't change how future emails from that sender are scored
    Read the full notes
  • 2.0.6.0

    minor

    Fresh-domain reputation: a live check of when a link's domain was registered, plus sharper statistics.

    • Live lookup of a domain's registration date against the public registry
    • Flags links and senders on domains registered within the last 30 days
    • Scam counter and recent-scams refinements in the popup
    • Sends only the link's bare domain name to the public registry - never your email content
    Read the full notes
  • 2.0.5.0

    minor

    Shortened-link resolution: see where a short link actually goes before you decide anything about it.

    • Detects links hidden behind URL shorteners
    • Resolves the real destination without following the link or downloading anything
    • Feeds the true domain into the existing reputation checks
    • Covers common shorteners such as bit.ly, tinyurl and t.co
    Read the full notes
  • 2.0.3.0

    minor

    QR codes in attachments: decode a QR code hidden in an image attachment, an inline image, a PDF or an Office attachment.

    • Decodes QR codes found in image attachments
    • Decodes QR codes in images embedded directly in the email body
    • Handles QR codes inside PDF and Office attachments
    • Works across the supported mail providers, including Gmail, Outlook, Yahoo and Zoho
    Read the full notes
  • 2.0.2.0

    minor

    First-time sender: a caution on email from a domain you have never received mail from before.

    • Flags email from a sender domain with no history in your inbox
    • Aimed at business email compromise and spoofed invoices
    • Works from a per-installation history that is never shared
    • Complements trusted contacts, which handles the opposite case
    Read the full notes
  • 2.0.1.0

    minor

    Trusted contacts: the extension learns which senders you actually correspond with, and stops over-flagging them.

    • Learns which sender domains you correspond with regularly
    • Three or more emails from a domain adds a trusted-contact signal
    • A trusted contact lowers the risk score by 10 points
    • Fewer false positives on senders you already know
    Read the full notes
  • 2.0.0.0

    major

    A phishing detection model that runs entirely in your browser, giving a second opinion on emails the rules are unsure about.

    • AI Deep Scan, a second opinion on emails that look suspicious but are not caught by the automated rules
    • A DistilBERT model trained for phishing detection, about 67 MB, downloaded once
    • Runs fully offline in your browser using WebAssembly
    • Returns its own verdict, a confidence score and written reasoning
    • No email content is sent to any server for analysis
    Read the full notes
  • 1.0.7.0

    minor

    More providers: Yahoo Mail, Zoho Mail including its regional domains, and iCloud Mail.

    • Yahoo Mail support
    • Zoho Mail support, including its regional domains
    • iCloud Mail support
    • Provider-specific handling for each service's layout and attachments
    Read the full notes
  • 1.0.2.0

    minor

    Anti-phishing codes: record the secret phrase a service uses, and know whether an email is genuinely from them.

    • Configure a personal anti-phishing code for each service you care about, such as a bank, an exchange or an email provider
    • Detects the labels providers use, including "anti-phishing code", "security phrase" and "your personal code"
    • A matching code shows a green confirmation and lowers the email's risk score
    • A wrong or missing code on an email that claims to carry one is treated as a critical scam signal
    Read the full notes
  • 1.0.0.0

    major

    The first public release: heuristic scanning in Gmail and Outlook, with a colour-coded badge on every email you open.

    • Heuristic scanning of every email you open in Gmail and Outlook
    • 28 independent checks for sender impersonation, deceptive links, urgency language and suspicious attachments
    • A colour-coded badge on each email: green for safe, yellow for suspicious, red for likely scam
    • A popover explaining every finding, with the exact text that triggered it
    • Mark a sender as safe, or report the email as a scam
    • Popup statistics showing how many emails have been scanned
    Read the full notes