Chrome extension for Gmail

See phishing risk before you click.

PhishSure scans the Gmail message you have open, checks sender, links, language, and technical signals, then explains what looks legitimate or suspicious in plain language.

In-Gmail scan Review the message you are already reading.
Clear reasoning Get risk signals and practical next steps.
Free and paid tiers Personal inboxes free, deeper checks for paid use.
PhishSure running inside Gmail on a laptop screen
What it does

Built for the moment when an email feels off.

PhishSure adds a scan bar to Gmail, fetches the opened message, and sends it to a backend service for structured phishing analysis. The result is returned directly inside Gmail with a risk view that is faster to interpret than reading raw headers or guessing from appearance alone.

Checks sender and message consistency

Flags mismatched names, suspicious domains, reply-to tricks, and language patterns that do not fit the message context.

Reviews links and attachments

Surfaces risky destinations, deceptive link text, and attachment clues that often show up in credential theft campaigns.

Explains the result

Shows a score, confidence, reasoning highlights, and an action recommendation instead of a black-box warning.

How it works

Simple flow, same Gmail tab.

The extension runs inside Gmail. When you open a message and start a scan, PhishSure reads the current email, submits it to the scanning API, and returns a result panel with the most relevant risk signals.

1

Open a Gmail message

The scan bar appears in the email view so you can assess a message without leaving your inbox.

2

Run the scan

PhishSure prefers the original message source when possible and falls back to visible page content when needed.

3

Review the verdict

See risk level, confidence, grouped reasons, and whether the scan used free or full access.

4

Install in Chrome

Download the extension files, unzip them, open chrome://extensions, enable Developer mode, and load the unpacked folder.

Privacy and permissions

Designed to be inspectable.

PhishSure requests only what it needs to scan Gmail and store your local paid key. The backend keeps operational data limited and focuses on risk analysis rather than broad mailbox access.

Gmail-only host access

The extension is scoped to https://mail.google.com/* and the configured backend API.

Local storage for access keys

The extension stores an optional paid API key locally in Chrome so scans can unlock detailed checks.

Backend-assisted analysis

Message content is sent to the backend for phishing evaluation. Free usage is rate limited to control abuse.

Minimal stored metadata

Stored scan data is limited to hashed private fields plus operational metadata for billing, feedback, and troubleshooting.

Read the complete Privacy Policy, including retention periods, service providers, and data-rights instructions.

FAQ

Questions users usually ask first.

Does it work without the backend?

No. The extension depends on the PhishSure backend to perform the actual phishing analysis.

Which inboxes can use the free tier?

Free usage is intended for personal inboxes. Paid access unlocks business-domain coverage and more detailed checks.

What browser is supported?

The current package is a Chrome extension built for Gmail in the browser.

What permissions should users expect?

Storage access for local key handling and host access for Gmail plus the configured backend API origin.

Try PhishSure on the same domain that serves its scanning API.

Use the extension for Gmail message scans, or download the package and set it up locally in a few minutes.

Get the extension