A detailed look at the email signals behind the answer.
isthisphish.help does not treat one clue as proof. It looks for patterns across the sender, links, wording, attachments, email metadata and the story the message is trying to tell. The reply explains the important clues in normal language.
Sender identity
Phishing often starts by pretending to be someone familiar. These checks ask whether the sender identity actually matches the brand, person or company shown in the email.
Checks whether a friendly name like "Microsoft Support" is hiding an unrelated email address.
Looks at the real sending address and whether the domain fits the organisation being claimed.
Flags cases where replies go somewhere different from the visible sender, especially to a personal or unrelated mailbox.
Where available, checks whether delivery bounce information points to a different or suspicious sender path.
Looks for domains that swap letters, add extra words, use odd endings or imitate a real brand at a glance.
Treats messages claiming to be a bank, supplier or large company with caution if they come from a free consumer mailbox.
Links and domains
Links are one of the biggest phishing giveaways. The tool checks whether the visible text, destination and surrounding story agree with each other.
Checks whether a link says it goes to one place but actually points somewhere else.
Flags shortened links because they hide the final destination until after you click.
Looks for links that do not match the claimed company, service or sender.
Explains cases like brand.example.com versus example-brand.com, where the important part of the domain can be easy to misread.
Treats raw number-based links as suspicious when a normal organisation would usually use a named domain.
Pays extra attention to links that lead to sign-in, password reset, payment, invoice or document download pages.
Flags links that push downloads when the email could have provided information directly or through a normal portal.
Treats QR-code-only actions carefully because they can move the user away from desktop protections and hide the destination.
Requested action
A phishing email usually wants something: credentials, money, access, personal data or a downloaded file. The requested action matters as much as the wording.
Flags emails that push you toward entering passwords, one-time codes or multi-factor authentication prompts.
Looks for urgent invoices, overdue balances, bank-detail changes, refund claims or payment rerouting.
Treats these as high-risk because they are common in scams and hard to reverse.
Flags instructions to install remote support tools, screen-sharing apps or security software from a link.
Checks for requests for ID documents, payroll details, tax data, customer lists or other information that should not be sent casually.
Looks for wording that asks you to ignore normal channels, keep it quiet or act outside the usual approval route.
Language and pressure
The wording is often engineered to make people move fast. The analysis looks for pressure, manipulation and wording that does not fit the claimed sender.
Flags phrases such as "act now", "final warning", "within 24 hours" or "your account will be closed".
Looks for threats of locked accounts, legal action, lost packages, penalties or missed payments.
Checks for prizes, refunds, grants, job offers or unexpected money that require clicking, paying or sharing details.
Compares the tone to what you would expect from a bank, delivery company, supplier or internal colleague.
Notes greetings like "Dear customer" when the sender should normally know who you are.
Flags broken phrasing, mixed brand names, inconsistent dates or wording that changes the story halfway through.
Attachments and files
Attachments can be used to hide malicious documents, fake invoices, credential forms or links that avoid simple link scanning.
Checks whether the attachment makes sense for the sender and conversation.
Flags file types that can carry scripts, macros, installers or hidden behaviour.
Treats ZIP, RAR and similar archives cautiously, especially when paired with urgency or passwords.
Flags attached web pages because they are often used for fake login forms.
Looks for common lures such as invoices, remittances, scanned documents, shared files and voicemail notifications.
Notes when an email gives a password for an attachment, since that can be used to avoid automated scanning.
Technical clues
When the forwarded email includes useful metadata, the tool can use it to support the explanation. The aim is to translate the technical clues rather than dump them on you.
Where available, checks whether the email passed common sender authentication checks.
Looks at whether the authenticated domain lines up with the visible sender domain.
Uses routing information, where present, to spot unusual delivery paths or infrastructure that does not fit the claimed sender.
Checks whether the technical fingerprints look consistent with the sender and type of message.
Notes timestamps that look strange, inconsistent or out of step with the message story.
Looks for clues that a personal-looking email may actually have been mass sent or generated by tooling.
Context and consistency
Some emails are suspicious because the story does not hold together. These checks look at whether the email feels consistent with the sender, timing and action requested.
Treats surprise password resets, deliveries, invoices and account warnings cautiously when there is no clear reason for them.
Looks for mixed logos, old branding, wrong product names or text that mentions multiple companies.
Checks for replies that seem to continue a real thread but suddenly introduce a link, attachment or payment change.
Flags requests that do not fit the supposed sender's job, department or normal authority.
Notes broken layouts, low-quality images, strange spacing or visual tricks that make links and buttons harder to inspect.
Suggests checking through a known website, saved contact, official app or existing channel instead of using the email's link.
How the result is written
The reply is meant to be useful, not theatrical. It should explain the important evidence and give a cautious next step.
The reply lists the main red flags and why they matter.
If parts of the message look ordinary, it can say that too. Not every odd email is a scam.
The result should help you decide whether to ignore, verify, report or avoid interacting.