Is This Email Phishing? Check for Free in Under a Minute
Phishing is behind 16% of breaches and 44% of AI-assisted attacks. Here are the signals you can check yourself in under a minute, and a free tool (forward to harry@protego.me) for the parts you can’t.

You get an email. A shipping notice, an invoice, a message from someone at work. It looks basically right, but something about it makes you pause before you click anything. That pause is doing its job: phishing was the entry point for 16% of all breaches in the 2026 Verizon Data Breach Investigations Report, and when attackers use AI tools to help write their messages, phishing is their most common opening move, used in 44% of those AI-assisted attacks (Help Net Security, Abnormal AI). AI-written phishing reads smoother than the broken-English scams people used to joke about, which is exactly why "it looked fine to me" is not a reliable test anymore.
The short version: you can check most of the real warning signs yourself in under a minute. For the parts that are genuinely hard to eyeball, like whether a domain actually passes authentication, we built a free tool that does it for you: forward the email to harry@protego.me and you get a plain-language verdict back.
What to check yourself, first
These are the signals that matter most, in the order they are easiest to check. None of them require any technical tools.
- Does the sending domain actually match the company? Look at the full address after the @, not just the display name. "Microsoft Support" is text anyone can type. "security@micros0ft-support.com" is the part that matters, and it is easy to skim right past a swapped letter or an extra word when you are reading quickly.
- Is it pushing you to act immediately? Real companies rarely give you 24 hours to avoid account suspension. Urgency is a deliberate design choice in phishing: it is meant to get you moving before you stop to check anything else.
- Does it want a password, a payment, or personal details? No legitimate company asks you to "confirm your password" by clicking a link in an email. If a message combines urgency with a request like this, treat that combination itself as the warning sign, not just either half alone.
- Do the links go where they claim to go? On desktop, hover over a link without clicking and look at the actual destination shown by your email client or browser. On mobile, press and hold instead of tapping. A link that displays "yourbank.com" but points somewhere else entirely is one of the more reliable tells, because attackers cannot fake the real destination the same way they can fake the display text.
- Would a reply actually go back to the real sender? Some phishing sets a hidden Reply-To address that is different from the visible From address, so your reply routes somewhere the attacker controls instead of back to whoever supposedly sent it. This one is genuinely hard to see just by looking at the email.
Why some of this is hard to check yourself
The links-and-urgency checks above cover a lot of ground, but a few real signals live entirely outside what an email client shows you. Whether a message actually passes the sender domain’s SPF, DKIM, and DMARC authentication lives in raw email headers most people have never opened. Whether a sending domain was registered three days ago, whether it already shows up on a threat intelligence blocklist, whether a QR code embedded in the message decodes to something malicious: none of that is visible from the inbox view. These are exactly the checks that benefit from being automated rather than eyeballed.
Forward it to us and we’ll check the rest
We built a free tool for exactly this: forward the suspicious email, as-is, to harry@protego.me. No signup, no form to fill out. A quick "checking now" acknowledgment lands right away so you know it went through, then a full results email follows with a color-coded risk score (green, orange, or red) and a plain-language breakdown of what was checked: sender authentication, look-alike domains, domain age and reputation, Reply-To mismatches, display name spoofing, suspicious links, QR codes hidden in images, and pressure-tactic language.
The email itself is deleted from our mailbox as soon as the check finishes. We only keep enough to track usage: the sender address, sender domain, subject line, and the score, never the body, links, or attachments. Full details are on the Email Verifier tool page.
What a LOW score actually means (and doesn’t)
A LOW score means these specific checks did not find anything suspicious, not that the email is guaranteed safe. No automated check, ours included, catches everything: a well-targeted attack from a genuinely compromised real account, for instance, can pass every one of these signals cleanly. Use the result as a strong first read, and when something still feels off even with a clean score, verify through a channel you already trust: call the person or company directly using a number you already have, not one from the email.
Frequently asked questions
Is the tool actually free?
Yes. Forward as many suspicious emails as you like to harry@protego.me. There is no account, no signup, and no payment involved.
How fast does the reply come back?
An acknowledgment arrives almost immediately, and the full results usually follow within seconds after that. A slower backup check runs every 10 minutes in case the fast path is ever unavailable, so a reply always arrives either way.
What happens to my email after it’s checked?
It is deleted from our mailbox right after the check finishes. We keep only the sender address, sender domain, subject line, and the score for usage tracking, never the body, links, or attachments.
Does forwarding versus retyping the email matter?
Yes. Forwarding preserves the technical sender details (authentication results, the real Reply-To address, routing headers) the checks rely on. Retyping the text or sending a screenshot strips all of that away and leaves only the content-based checks to go on.
What if I own the domain and want to check if it can be spoofed, not just check a message I received?
That is a different question, and we have a separate free tool for it: the Email Security Checker tests whether your own domain’s SPF, DKIM, and DMARC records would let someone spoof your address.
Here are some ads because we need to pay the bills somehow.
Cloud Security Checklist
A 20-point hardening checklist for AWS, Azure, and GCP workloads.
No spam. Unsubscribe anytime.
Continue Learning
SOC Analyst Level 1 Roadmap
Get job-ready for your first Security Operations Center role.
Microsoft Cloud Solution Architect
Cloud Solution Architect with deep expertise in Microsoft Azure and a strong background in systems and IT infrastructure. Passionate about cloud technologies, security best practices, and helping organizations modernize their infrastructure.
Share this article
Questions & Answers
Related Articles
Need Help with Your Security?
Our team of security experts can help you implement the strategies discussed in this article.
Contact Us