Pressure and stated consequences
Time limits, urgent instructions, and stated account or service consequences can make it harder to pause before acting.
Evidence-first email triage
Choose a local synthetic example or paste email text. PhishLens helps you review observable cues locally and choose an independent way to verify the request.
Start with a sample or paste an email below. The local report comes first.
Browser-local deterministic analysis Your initial report is produced in the browser.
Explicit-consent AI explanation The optional layer is requested separately after a local report.
No link, attachment, or inbox access PhishLens does not open supplied links or connect to email.
Input workspace
Try a local synthetic example, or paste your own email below.
Local report
Review the message without opening its link or attachment, then use the report to choose what to verify next.
How it works
PhishLens keeps the learning sequence simple: local evidence first, independent verification next, and an optional explanation only after a report exists.
Start with a local synthetic example or paste email text into the workspace.
Read the configured observable patterns, the supporting text, and why each cue matters.
Use a known website or trusted contact path instead of a link or contact detail supplied in the message.
After the local report, an optional explanation clearly states its source and cannot change the local findings.
What PhishLens checks
The browser-only engine evaluates the text you provide against a small, transparent rule set. It does not infer intent, identity, or a definitive outcome.
Time limits, urgent instructions, and stated account or service consequences can make it harder to pause before acting.
Requests for passwords, account codes, recovery codes, authentication links, or corroborated account details are shown with their exact text evidence.
Payment, bank-detail, gift-card, crypto, or wire requests are useful prompts to confirm through a known vendor or contact path.
A claimed authority role or broad salutation is shown only when it appears alongside pressure or a sensitive request.
Account restriction, refund, reward, or prize language is shown only when paired with a visible request or pressure cue.
The engine can show conservative digit-for-letter patterns, internationalized formats, or an unclear pasted address without inferring identity.
URL presence remains informational on its own. One visible structure detail, such as user information, an IP host, or an unusual port, may be shown separately without opening the URL.
A filename is shown only when message text asks the reader to open or download a high-risk extension. No attachment is opened or inspected.
When locally comparable domains differ, the report shows that detail for independent verification. Different domains can have legitimate reasons.
Safety boundaries
PhishLens is deliberately narrow. The local report helps a reader decide what to verify next without taking action on their behalf.
Local deterministic analysis runs in the browser. The optional explanation is separate, requires explicit consent, and never replaces the local report.
What PhishLens does not do
Observable cues are learning prompts, not a definitive email verdict.
PhishLens does not open, fetch, or inspect content at a supplied link's destination.
Attachments are not opened, executed, uploaded, or processed.
The app does not connect to email accounts or mailboxes.
PhishLens does not store submitted email content or add telemetry.
About PhishLens
PhishLens is a security-sensitive educational prototype built for transparent email triage—not a company or enterprise security product. Its code, local rules, and stated limits are meant to be inspectable.
Focused contributions are welcome when they preserve the deterministic-first, privacy, and security boundaries.
Open source
Explore the source, report a problem, or contribute a focused improvement.