What the tool checks

A detailed look at the email signals behind the answer.

isthisphish.help does not treat one clue as proof. It looks for patterns across the sender, links, wording, attachments, email metadata and the story the message is trying to tell. The reply explains the important clues in normal language.

Sender identity

Phishing often starts by pretending to be someone familiar. These checks ask whether the sender identity actually matches the brand, person or company shown in the email.

Display name

Checks whether a friendly name like "Microsoft Support" is hiding an unrelated email address.

Sender address

Looks at the real sending address and whether the domain fits the organisation being claimed.

Reply-to address

Flags cases where replies go somewhere different from the visible sender, especially to a personal or unrelated mailbox.

Return path

Where available, checks whether delivery bounce information points to a different or suspicious sender path.

Lookalike domains

Looks for domains that swap letters, add extra words, use odd endings or imitate a real brand at a glance.

Free mailbox mismatch

Treats messages claiming to be a bank, supplier or large company with caution if they come from a free consumer mailbox.

Requested action

A phishing email usually wants something: credentials, money, access, personal data or a downloaded file. The requested action matters as much as the wording.

Password or MFA request

Flags emails that push you toward entering passwords, one-time codes or multi-factor authentication prompts.

Payment pressure

Looks for urgent invoices, overdue balances, bank-detail changes, refund claims or payment rerouting.

Gift card or crypto request

Treats these as high-risk because they are common in scams and hard to reverse.

Remote access request

Flags instructions to install remote support tools, screen-sharing apps or security software from a link.

Sensitive information request

Checks for requests for ID documents, payroll details, tax data, customer lists or other information that should not be sent casually.

Bypass normal process

Looks for wording that asks you to ignore normal channels, keep it quiet or act outside the usual approval route.

Language and pressure

The wording is often engineered to make people move fast. The analysis looks for pressure, manipulation and wording that does not fit the claimed sender.

Urgency

Flags phrases such as "act now", "final warning", "within 24 hours" or "your account will be closed".

Threats

Looks for threats of locked accounts, legal action, lost packages, penalties or missed payments.

Too-good-to-be-true claims

Checks for prizes, refunds, grants, job offers or unexpected money that require clicking, paying or sharing details.

Unusual tone

Compares the tone to what you would expect from a bank, delivery company, supplier or internal colleague.

Generic greeting

Notes greetings like "Dear customer" when the sender should normally know who you are.

Awkward or inconsistent wording

Flags broken phrasing, mixed brand names, inconsistent dates or wording that changes the story halfway through.

Attachments and files

Attachments can be used to hide malicious documents, fake invoices, credential forms or links that avoid simple link scanning.

Unexpected attachment

Checks whether the attachment makes sense for the sender and conversation.

Risky file types

Flags file types that can carry scripts, macros, installers or hidden behaviour.

Compressed files

Treats ZIP, RAR and similar archives cautiously, especially when paired with urgency or passwords.

HTML attachments

Flags attached web pages because they are often used for fake login forms.

Invoice and document bait

Looks for common lures such as invoices, remittances, scanned documents, shared files and voicemail notifications.

Password-protected files

Notes when an email gives a password for an attachment, since that can be used to avoid automated scanning.

Technical clues

When the forwarded email includes useful metadata, the tool can use it to support the explanation. The aim is to translate the technical clues rather than dump them on you.

SPF, DKIM and DMARC

Where available, checks whether the email passed common sender authentication checks.

Authentication alignment

Looks at whether the authenticated domain lines up with the visible sender domain.

Received path

Uses routing information, where present, to spot unusual delivery paths or infrastructure that does not fit the claimed sender.

Message ID and mailer clues

Checks whether the technical fingerprints look consistent with the sender and type of message.

Date and timezone oddities

Notes timestamps that look strange, inconsistent or out of step with the message story.

Bulk or automated sending signs

Looks for clues that a personal-looking email may actually have been mass sent or generated by tooling.

Forwarded emails do not always include every header or technical detail. If a signal is missing, the result should say so or avoid overclaiming from it.

Context and consistency

Some emails are suspicious because the story does not hold together. These checks look at whether the email feels consistent with the sender, timing and action requested.

Unexpected message

Treats surprise password resets, deliveries, invoices and account warnings cautiously when there is no clear reason for them.

Brand mismatch

Looks for mixed logos, old branding, wrong product names or text that mentions multiple companies.

Conversation hijack signs

Checks for replies that seem to continue a real thread but suddenly introduce a link, attachment or payment change.

Role mismatch

Flags requests that do not fit the supposed sender's job, department or normal authority.

Formatting oddities

Notes broken layouts, low-quality images, strange spacing or visual tricks that make links and buttons harder to inspect.

Safe way to verify

Suggests checking through a known website, saved contact, official app or existing channel instead of using the email's link.

How the result is written

The reply is meant to be useful, not theatrical. It should explain the important evidence and give a cautious next step.

What looks suspicious

The reply lists the main red flags and why they matter.

What looks normal

If parts of the message look ordinary, it can say that too. Not every odd email is a scam.

What to do next

The result should help you decide whether to ignore, verify, report or avoid interacting.

No phishing tool can guarantee that every email is safe or unsafe. The goal is to make the risk easier to understand so you can make a better decision.