PhishSweep
Phishing Email Detector for Gmail
A plain warning on the emails trying to trick you.
PhishSweep adds a Safe, Caution or Likely phishing badge to each email you open in Gmail, and names the trick: fake invoice, account suspension, parcel fee.
- Likely phishing · account suspension
Your account has been limited. Verify within 24 hours to avoid permanent closure.
- Explained
The sender’s name says PayPal but the address does not. The link goes to a different site than it shows. It pressures you to act fast.
- Caution · invoice fraud pattern
Please note our bank details have changed for this month’s invoice.
- Safe
New arrivals for September, and a reading list from our staff.
The problem
Spam filters catch the bulk. The ones aimed at you get through
A well-written fake invoice or a note from "the boss" looks ordinary to a filter. Spotting it means reading the message the way a careful person would, and doing that for every email as it opens.
Names the trick
Not just a colour: invoice fraud, credential harvesting, parcel fee, fake support, a colleague asking for a favour.
Shows its working
Which signals it saw: a sender name that does not match the address, a link that goes somewhere else, pressure to act now.
Points you to help
Links to report to Action Fraud, Scamwatch or the FTC, by country.
How it will work
Three steps, and you stay in charge.
- 1
Open an email
PhishSweep reads the message you have opened in Gmail: sender, subject, text and where the links point.
- 2
A badge appears under the subject
Safe, Caution or Likely phishing, within about a second.
- 3
Red badges explain themselves
The tactic, the signals behind it, and what to do next.
Where it will run
Where it will run
Gmail in Chrome first.
- Gmail on the web
- mail.google.com, for personal and Workspace accounts.
- Later
- Outlook on the web.
- For teams
- Installable through the Google Workspace admin console.
Privacy, plainly
What it reads, and what it never does.
This one reads email, so it has to be exact about what that means.
What it will read
- Only the email you have open: sender, subject, text, and the domains its links point to
- Nothing until you open a message
What it never touches
- Your inbox as a whole, your contacts or your sent mail
- Attachments
- The Gmail API or your Google account: it has no access to either and asks for none
The text of the opened email is sent to our server and on to the AI model that judges it. We will publish exactly how long each party keeps it before launch, and we will not launch until that answer is one we are comfortable putting in writing.
Planned pricing
Planned pricing. It may change before launch, and waitlist members hear first.
Free
$0
- Around 100 emails a day
Personal
$3.99 a month
- No daily limit
- Explanations on every warning
Small business
$2 per seat a month
- Deployed by your Workspace admin
- Aimed at accounts-payable teams
Nothing is charged for joining the waitlist.
Does it replace Gmail’s spam filter?
No. It works alongside it, on the messages that reach your inbox.
Does it need access to my Google account?
No. It reads the message on your screen, the way you do. It never asks for Gmail API access or a Google sign-in.
Can it be wrong?
Yes, in both directions. A Safe badge is not a guarantee, and a warning is a reason to check, not proof. It always shows you why.
When will it be ready?
After FakeCatch and BaitCatch. Join the waitlist and you get one email on launch day.
Thinking of someone who clicks on everything?
Leave your email and you will hear once, when it is ready.