PARTLY

As of 13 August 2026, AI can only partly check whether an email is a phishing attempt.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

30 minutesto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita colleague

What the alternative costsNo priced alternative is supplied in the available tool data.

If this goes wrong, you may click a malicious link, disclose information or delay reporting a real attack.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.

    How to actually do it

    1. Leave the message unopened if possible, and do not click links, open attachments or reply to it.
    2. Open your approved mail client and copy the visible sender address, subject, message text, link text and attachment names without opening any link or file.
    3. Use the mail client's option for viewing raw headers, copy them only if your workplace policy allows it, and remove passwords, tokens and unnecessary personal information.
    4. Paste the copied material into the prompt in an approved chatbot, including your organisation's phishing reporting process if you have it.
    5. Compare the model's evidence against the actual sender domain, the displayed link destinations and the context of the request, without visiting a suspicious destination.
    6. Confirm the decision with your IT or security contact through a separate trusted channel, then use your organisation's reporting or quarantine process and delete the message only when instructed.

    Prompt

    Assess the email below for signs of phishing. Treat this as triage, not proof. Do not open any links, download attachments or claim to have checked live websites, domains, DNS, malware or sender reputation. Use only the text and technical details I provide.
    
    Return:
    1. A classification: likely phishing, suspicious, probably legitimate, or cannot determine.
    2. A confidence level of low, medium or high, with no invented probability.
    3. A table of the specific evidence, quoting the relevant parts of the email and explaining why each point matters.
    4. Any missing evidence that would materially change the assessment, such as raw headers, the real link destination or an attachment analysis.
    5. Safe next actions for a UK workplace, including whether to avoid replying, avoid clicking, report it through the organisation's process and contact the supposed sender through a separate trusted channel.
    6. A short explanation of what you cannot verify from this material.
    
    Do not tell me to test a link by visiting it. Do not ask me to enter credentials. If the email requests payment, password changes, confidential files or an urgent transfer, state that a human security or IT colleague must make the final decision.
    
    Organisation reporting process, if known: [PASTE PROCESS OR WRITE UNKNOWN]
    Email text and visible details:
    [PASTE EMAIL]
    Raw headers, if approved for sharing:
    [PASTE HEADERS OR WRITE NOT AVAILABLE]
    Link text and displayed destinations, copied without opening them:
    [PASTE LINKS OR WRITE NONE]
    Attachment names and file types, without opening them:
    [PASTE ATTACHMENT DETAILS OR WRITE NONE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: real time truth, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can AI tell if an email is phishing?
It can assess supplied wording, sender details, headers and link text and point out suspicious indicators. It cannot prove that a message is safe or inspect live links and attachments, so a workplace IT or security colleague must make the final decision.
Is it safe to paste a suspicious email into ChatGPT?
Only use a chatbot approved by your employer and remove passwords, tokens and unnecessary personal or confidential information first. Do not paste sensitive workplace content into a public service if your organisation's policy does not allow it.
What should I do if AI says an email is phishing?
Do not click, reply, open an attachment or use a link in the message. Confirm the assessment through your organisation's IT or security process and report the email using the approved method.
Can AI check email links?
AI can compare visible link text with a destination you copy without opening it and explain common warning signs. It cannot safely establish the current contents or reputation of a live destination, so use your organisation's email security tools or ask IT to investigate it.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.