Evidence-first email triage

Understand an email before you act.

Choose a local synthetic example or paste email text. PhishLens helps you review observable cues locally and choose an independent way to verify the request.

Start with a sample or paste an email below. The local report comes first.

Browser-local deterministic analysis Your initial report is produced in the browser.

Explicit-consent AI explanation The optional layer is requested separately after a local report.

No link, attachment, or inbox access PhishLens does not open supplied links or connect to email.

Input workspace

Start with a sample or paste email text

Try a local synthetic example, or paste your own email below.

Choose a local synthetic example, or enter your own text below.

Local report

Start with a sample or paste an email to see a local evidence report.

Review the message without opening its link or attachment, then use the report to choose what to verify next.

How it works

A calm path from message to independent verification.

PhishLens keeps the learning sequence simple: local evidence first, independent verification next, and an optional explanation only after a report exists.

  1. 01

    Choose or paste

    Start with a local synthetic example or paste email text into the workspace.

  2. 02

    Review local evidence

    Read the configured observable patterns, the supporting text, and why each cue matters.

  3. 03

    Verify independently

    Use a known website or trusted contact path instead of a link or contact detail supplied in the message.

  4. 04

    Choose an explanation

    After the local report, an optional explanation clearly states its source and cannot change the local findings.

What PhishLens checks

Configured observable patterns, shown with their evidence.

The browser-only engine evaluates the text you provide against a small, transparent rule set. It does not infer intent, identity, or a definitive outcome.

Pressure and stated consequences

Time limits, urgent instructions, and stated account or service consequences can make it harder to pause before acting.

Credential and authentication requests

Requests for passwords, account codes, recovery codes, authentication links, or corroborated account details are shown with their exact text evidence.

Financial requests

Payment, bank-detail, gift-card, crypto, or wire requests are useful prompts to confirm through a known vendor or contact path.

Role or greeting paired with a request

A claimed authority role or broad salutation is shown only when it appears alongside pressure or a sensitive request.

Account, refund, and reward pressure

Account restriction, refund, reward, or prize language is shown only when paired with a visible request or pressure cue.

Sender-domain structure

The engine can show conservative digit-for-letter patterns, internationalized formats, or an unclear pasted address without inferring identity.

Supplied URL structure

URL presence remains informational on its own. One visible structure detail, such as user information, an IP host, or an unusual port, may be shown separately without opening the URL.

Referenced high-risk file types

A filename is shown only when message text asks the reader to open or download a high-risk extension. No attachment is opened or inspected.

Sender and supplied-URL comparison

When locally comparable domains differ, the report shows that detail for independent verification. Different domains can have legitimate reasons.

Safety boundaries

Useful context without hidden access or certainty claims.

PhishLens is deliberately narrow. The local report helps a reader decide what to verify next without taking action on their behalf.

What stays in your control

Local deterministic analysis runs in the browser. The optional explanation is separate, requires explicit consent, and never replaces the local report.

What PhishLens does not do

  • No definitive verdicts

    Observable cues are learning prompts, not a definitive email verdict.

  • No link destinations opened

    PhishLens does not open, fetch, or inspect content at a supplied link's destination.

  • No attachment processing

    Attachments are not opened, executed, uploaded, or processed.

  • No inbox connection

    The app does not connect to email accounts or mailboxes.

  • No content retention

    PhishLens does not store submitted email content or add telemetry.

About PhishLens

An open-source learning prototype for transparent email triage.

PhishLens is a security-sensitive educational prototype built for transparent email triage—not a company or enterprise security product. Its code, local rules, and stated limits are meant to be inspectable.

Inspect the codeReport a problem

Focused contributions are welcome when they preserve the deterministic-first, privacy, and security boundaries.

Open source

Explore the source, report a problem, or contribute a focused improvement.

Repository Issues