05 / PHISHING & URLS
Plain-language risk analysis
Inspect suspicious messages, links, domains, certificates, and connection metadata without requiring users to interpret raw technical signals.
Email-file analysis
Browse to a saved .eml message and inspect its sender, headers, links, and attachments.
Header authentication checks
Reviews SPF, DKIM, DMARC, routing, and sender inconsistencies.
QR-code lure detection
Looks for QR codes that may conceal phishing destinations.
Link and redirect inspection
Examines redirect chains, risky terms, suspicious patterns, and final destinations.
Lookalike-domain detection
Flags domains designed to imitate a familiar brand or service.
Domain and IP reputation
Combines local analysis and configured reputation signals for clearer risk context.
TLS certificate checks
Reviews certificate validity and expiration information for a domain.
Verbal risk levels
Pairs the score with No Risk Detected, Low, Medium, or High and explains what the level means.
Monitor-only network protection
Observes hostnames, IPs, TLS SNI, certificates, and traffic volume without decrypting HTTPS.
Trusted sender, domain, and IP lists
Lets users approve reviewed sources and reduce repeat alerts.