Cyber Intelligence
Security Tools6 min read

Is This Email Phishing? Check for Free in Under a Minute

Phishing is behind 16% of breaches and 44% of AI-assisted attacks. Here are the signals you can check yourself in under a minute, and a free tool (forward to harry@protego.me) for the parts you can’t.

I
Microsoft Cloud Solution Architect
A glowing blue envelope being scanned by a radar beam, flanked by shield and checkmark icons and a green-to-red risk gauge, on a dark circuit-board background
A glowing blue envelope being scanned by a radar beam, flanked by shield and checkmark icons and a green-to-red risk gauge, on a dark circuit-board background
phishingemail securityemail verifiersocial engineeringsecurity awareness

You get an email. A shipping notice, an invoice, a message from someone at work. It looks basically right, but something about it makes you pause before you click anything. That pause is doing its job: phishing was the entry point for 16% of all breaches in the 2026 Verizon Data Breach Investigations Report, and when attackers use AI tools to help write their messages, phishing is their most common opening move, used in 44% of those AI-assisted attacks (Help Net Security, Abnormal AI). AI-written phishing reads smoother than the broken-English scams people used to joke about, which is exactly why "it looked fine to me" is not a reliable test anymore.

The short version: you can check most of the real warning signs yourself in under a minute. For the parts that are genuinely hard to eyeball, like whether a domain actually passes authentication, we built a free tool that does it for you: forward the email to harry@protego.me and you get a plain-language verdict back.

What to check yourself, first

These are the signals that matter most, in the order they are easiest to check. None of them require any technical tools.

  • Does the sending domain actually match the company? Look at the full address after the @, not just the display name. "Microsoft Support" is text anyone can type. "security@micros0ft-support.com" is the part that matters, and it is easy to skim right past a swapped letter or an extra word when you are reading quickly.
  • Is it pushing you to act immediately? Real companies rarely give you 24 hours to avoid account suspension. Urgency is a deliberate design choice in phishing: it is meant to get you moving before you stop to check anything else.
  • Does it want a password, a payment, or personal details? No legitimate company asks you to "confirm your password" by clicking a link in an email. If a message combines urgency with a request like this, treat that combination itself as the warning sign, not just either half alone.
  • Do the links go where they claim to go? On desktop, hover over a link without clicking and look at the actual destination shown by your email client or browser. On mobile, press and hold instead of tapping. A link that displays "yourbank.com" but points somewhere else entirely is one of the more reliable tells, because attackers cannot fake the real destination the same way they can fake the display text.
  • Would a reply actually go back to the real sender? Some phishing sets a hidden Reply-To address that is different from the visible From address, so your reply routes somewhere the attacker controls instead of back to whoever supposedly sent it. This one is genuinely hard to see just by looking at the email.

Why some of this is hard to check yourself

The links-and-urgency checks above cover a lot of ground, but a few real signals live entirely outside what an email client shows you. Whether a message actually passes the sender domain’s SPF, DKIM, and DMARC authentication lives in raw email headers most people have never opened. Whether a sending domain was registered three days ago, whether it already shows up on a threat intelligence blocklist, whether a QR code embedded in the message decodes to something malicious: none of that is visible from the inbox view. These are exactly the checks that benefit from being automated rather than eyeballed.

Forward it to us and we’ll check the rest

We built a free tool for exactly this: forward the suspicious email, as-is, to harry@protego.me. No signup, no form to fill out. A quick "checking now" acknowledgment lands right away so you know it went through, then a full results email follows with a color-coded risk score (green, orange, or red) and a plain-language breakdown of what was checked: sender authentication, look-alike domains, domain age and reputation, Reply-To mismatches, display name spoofing, suspicious links, QR codes hidden in images, and pressure-tactic language.

The email itself is deleted from our mailbox as soon as the check finishes. We only keep enough to track usage: the sender address, sender domain, subject line, and the score, never the body, links, or attachments. Full details are on the Email Verifier tool page.

What a LOW score actually means (and doesn’t)

A LOW score means these specific checks did not find anything suspicious, not that the email is guaranteed safe. No automated check, ours included, catches everything: a well-targeted attack from a genuinely compromised real account, for instance, can pass every one of these signals cleanly. Use the result as a strong first read, and when something still feels off even with a clean score, verify through a channel you already trust: call the person or company directly using a number you already have, not one from the email.

Frequently asked questions

Is the tool actually free?

Yes. Forward as many suspicious emails as you like to harry@protego.me. There is no account, no signup, and no payment involved.

How fast does the reply come back?

An acknowledgment arrives almost immediately, and the full results usually follow within seconds after that. A slower backup check runs every 10 minutes in case the fast path is ever unavailable, so a reply always arrives either way.

What happens to my email after it’s checked?

It is deleted from our mailbox right after the check finishes. We keep only the sender address, sender domain, subject line, and the score for usage tracking, never the body, links, or attachments.

Does forwarding versus retyping the email matter?

Yes. Forwarding preserves the technical sender details (authentication results, the real Reply-To address, routing headers) the checks rely on. Retyping the text or sending a screenshot strips all of that away and leaves only the content-based checks to go on.

What if I own the domain and want to check if it can be spoofed, not just check a message I received?

That is a different question, and we have a separate free tool for it: the Email Security Checker tests whether your own domain’s SPF, DKIM, and DMARC records would let someone spoof your address.

Here are some ads because we need to pay the bills somehow.

Free download

Cloud Security Checklist

A 20-point hardening checklist for AWS, Azure, and GCP workloads.

No spam. Unsubscribe anytime.

Continue Learning

SOC Analyst Level 1 Roadmap

Get job-ready for your first Security Operations Center role.

Start the Beginner Path10h · 4 topics · 10 quiz questions
I

Microsoft Cloud Solution Architect

Cloud Solution Architect with deep expertise in Microsoft Azure and a strong background in systems and IT infrastructure. Passionate about cloud technologies, security best practices, and helping organizations modernize their infrastructure.

Share this article

Questions & Answers

Ask a Question

0/2000 characters

Your email is used for moderation only and will not be displayed.

Related Articles

Need Help with Your Security?

Our team of security experts can help you implement the strategies discussed in this article.

Contact Us