Phishing

Real-time detection you can argue with

Real-time phishing detection that runs in your browser. It reads the message as well as the address, quotes the phrase that fired, and shows its reasoning.

Every finding traced to the rule that fired. No confidence score you have to take on trust, and no model you cannot question.

Runs on this deviceNothing uploadedSame message, same result
MESSAGEYour account closes tonight.Confirm the six-digit code.
3rules firedEvery phrase shown
Check it here

Paste the whole message

Include the greeting, the request and any address. It does not need to contain a link.

Phishing check Analysed on this device · never sent · never fetched
or paste the text below
✓

Read on this device. Screenshots are never uploaded or stored. Review and correct the extracted text before checking it.

Try a sample
Why it is built this way

A number you cannot check is not much use

Most phishing tools hand you a probability — “94% likely phishing” — and nothing else. That tells you what the machine concluded, not why, which means you cannot check it, cannot argue with it when it is wrong, and cannot learn anything from it. This one is a library of written rules: every point in the score opens to the phrase that triggered it.

Black-box scoreOne number
  • A probability
  • You cannot tell why it was wrong
  • Training data you never see
  • Usually runs on a server
  • The same message may vary
PrivateCueInspectable findings
  • Each finding quotes the words that fired it
  • You can judge the phrase yourself
  • Published guidance, cited on the page
  • Your browser — nothing uploaded
  • Always identical and deterministic

To be fair to the other approach: a model can catch phrasing nobody has written a rule for yet. That is a real advantage, and it is why the library is edited by hand and versioned in public — a new script becomes a written rule with a source, not a weight nobody can read.

The gap

Most phishing is not a link problem

A URL checker scores an address. It cannot see the message that asks you to reply with the six-digit code, or the one that says your account closes tonight. Those carry no link at all, and they are the fastest-growing kind — because they cost the sender nothing to send and ask nothing of your suspicion.

The wording

Does it ask for a code, a password or card details? Does it threaten the account? Does it invent a deadline? Most phishing asks for something in plain text long before it sends you anywhere.

The address

Does the domain belong to the institution the message names? Is it a lookalike, a homoglyph, a bare IP, a shortener? Read as text only — never visited, never resolved.

The two together

A message that names a bank and links somewhere else is the signature finding — invisible to a checker that only scores the address. The combination is worth more than either alone.

What it flags

The shapes, and what each one is worth

Signals are weighted one to three, capped by group so a message cannot score high by repeating itself, and every finding quotes the words that triggered it.

3Asks for a one-time code, 2FA code or OTP

A real institution never asks you to read out the code it just sent. The code is the thing being stolen.

3Asks for a password, PIN, card code or identifier

Possessing it is the entire point of the message.

3Asks you to verify, confirm or update an account

The most common opening in phishing: it borrows the vocabulary of a security notice.

2Threatens the account — suspended, closed, frozen

The consequence that short-circuits checking.

2Manufactures a deadline

Urgency is the mechanism. It removes the pause in which you would check.

2Claims unusual or unauthorised activity

The pretext that justifies the demand.

3Names an institution, links somewhere else

The signature finding — invisible to a checker that only scores the address.

1Generic greeting, invoice lure, off-platform push

Supporting only. Capped low, because none of them prove anything alone.

Honesty

What this will not claim

The same rules that govern the rest of PrivateCue apply here. A tool that only tells you what you already fear is not a tool.

  • It never visits, resolves or looks anything up — so it cannot tell you a site's age, reputation or whether it is currently live.
  • It never declares a named site or company fraudulent. A report describes a pattern in a message; it is never a verdict on a business.
  • A phisher can write clean, calm English, and a real institution can send an alarming message. The wording is evidence, not proof.
  • It is deterministic, not predictive: the same message always produces the same findings, and every one of them names the phrase that fired.
Act now

If you have already sent money

Call your bank today using the number on your card, ask for the fraud department, and file a report the same day. Recovery windows for transfers and crypto can close within hours.

Watch for the second approach. Someone may offer to recover your money while claiming to be the FBI, Interpol or another agency. That is a recovery scam. Legitimate agencies do not contact victims to sell paid recovery.

FREE Open the Recovery PackNo account. No card. No payment.

Check the message you are looking at

Paste it into the phishing tab — the whole thing, greeting and all. It runs on this device, in the time it takes to blink, and nothing is uploaded.