PhishSweep

PhishSweep

Phishing Email Detector for Gmail

In development

A plain warning on the emails trying to trick you.

PhishSweep adds a Safe, Caution or Likely phishing badge to each email you open in Gmail, and names the trick: fake invoice, account suspension, parcel fee.

One launch email, nothing else. What we keep.

  1. billing@paypa1-secure.example

    Your account has been limited. Verify within 24 hours to avoid permanent closure.

    Likely phishing · account suspension
  2. Why

    The sender’s name says PayPal but the address does not. The link goes to a different site than it shows. It pressures you to act fast.

    Explained
  3. accounts@your-supplier.example

    Please note our bank details have changed for this month’s invoice.

    Caution · invoice fraud pattern
  4. newsletter@bookshop.example

    New arrivals for September, and a reading list from our staff.

    Safe
Illustration · how PhishSweep labels an opened email

The problem

Spam filters catch the bulk. The ones aimed at you get through

A well-written fake invoice or a note from "the boss" looks ordinary to a filter. Spotting it means reading the message the way a careful person would, and doing that for every email as it opens.

Names the trick

Not just a colour: invoice fraud, credential harvesting, parcel fee, fake support, a colleague asking for a favour.

Shows its working

Which signals it saw: a sender name that does not match the address, a link that goes somewhere else, pressure to act now.

Points you to help

Links to report to Action Fraud, Scamwatch or the FTC, by country.

How it will work

Three steps, and you stay in charge.

  1. 1

    Open an email

    PhishSweep reads the message you have opened in Gmail: sender, subject, text and where the links point.

  2. 2

    A badge appears under the subject

    Safe, Caution or Likely phishing, within about a second.

  3. 3

    Red badges explain themselves

    The tactic, the signals behind it, and what to do next.

Where it will run

Where it will run

Gmail in Chrome first.

Gmail on the web
mail.google.com, for personal and Workspace accounts.
Later
Outlook on the web.
For teams
Installable through the Google Workspace admin console.

Privacy, plainly

What it reads, and what it never does.

This one reads email, so it has to be exact about what that means.

What it will read

  • Only the email you have open: sender, subject, text, and the domains its links point to
  • Nothing until you open a message

What it never touches

  • Your inbox as a whole, your contacts or your sent mail
  • Attachments
  • The Gmail API or your Google account: it has no access to either and asks for none

The text of the opened email is sent to our server and on to the AI model that judges it. We will publish exactly how long each party keeps it before launch, and we will not launch until that answer is one we are comfortable putting in writing.

Planned pricing

Planned pricing. It may change before launch, and waitlist members hear first.

Free

$0

  • Around 100 emails a day

Small business

$2 per seat a month

  • Deployed by your Workspace admin
  • Aimed at accounts-payable teams

Nothing is charged for joining the waitlist.

Questions

Fair things to ask.

Something else? support@codewithkolin.com

Does it replace Gmail’s spam filter?

No. It works alongside it, on the messages that reach your inbox.

Does it need access to my Google account?

No. It reads the message on your screen, the way you do. It never asks for Gmail API access or a Google sign-in.

Can it be wrong?

Yes, in both directions. A Safe badge is not a guarantee, and a warning is a reason to check, not proof. It always shows you why.

When will it be ready?

After FakeCatch and BaitCatch. Join the waitlist and you get one email on launch day.

Thinking of someone who clicks on everything?

Leave your email and you will hear once, when it is ready.

One launch email, nothing else. What we keep.