As of 13 August 2026, AI can only partly check whether an email is a phishing attempt.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
30 minutesto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita colleague
What the alternative costsNo priced alternative is supplied in the available tool data.
If this goes wrong, you may click a malicious link, disclose information or delay reporting a real attack.
What to actually do
Hand it to a person
The route this page recommends
A person who owns the outcome does this end to end, worth it when the failure is dear.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.
How to actually do it
- Leave the message unopened if possible, and do not click links, open attachments or reply to it.
- Open your approved mail client and copy the visible sender address, subject, message text, link text and attachment names without opening any link or file.
- Use the mail client's option for viewing raw headers, copy them only if your workplace policy allows it, and remove passwords, tokens and unnecessary personal information.
- Paste the copied material into the prompt in an approved chatbot, including your organisation's phishing reporting process if you have it.
- Compare the model's evidence against the actual sender domain, the displayed link destinations and the context of the request, without visiting a suspicious destination.
- Confirm the decision with your IT or security contact through a separate trusted channel, then use your organisation's reporting or quarantine process and delete the message only when instructed.
Prompt
Assess the email below for signs of phishing. Treat this as triage, not proof. Do not open any links, download attachments or claim to have checked live websites, domains, DNS, malware or sender reputation. Use only the text and technical details I provide. Return: 1. A classification: likely phishing, suspicious, probably legitimate, or cannot determine. 2. A confidence level of low, medium or high, with no invented probability. 3. A table of the specific evidence, quoting the relevant parts of the email and explaining why each point matters. 4. Any missing evidence that would materially change the assessment, such as raw headers, the real link destination or an attachment analysis. 5. Safe next actions for a UK workplace, including whether to avoid replying, avoid clicking, report it through the organisation's process and contact the supposed sender through a separate trusted channel. 6. A short explanation of what you cannot verify from this material. Do not tell me to test a link by visiting it. Do not ask me to enter credentials. If the email requests payment, password changes, confidential files or an urgent transfer, state that a human security or IT colleague must make the final decision. Organisation reporting process, if known: [PASTE PROCESS OR WRITE UNKNOWN] Email text and visible details: [PASTE EMAIL] Raw headers, if approved for sharing: [PASTE HEADERS OR WRITE NOT AVAILABLE] Link text and displayed destinations, copied without opening them: [PASTE LINKS OR WRITE NONE] Attachment names and file types, without opening them: [PASTE ATTACHMENT DETAILS OR WRITE NONE]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot confirm a domain's current reputation, whether a link redirects to a malicious site or whether an attachment contains malware without approved security tools and live investigation.
- AI cannot tell whether a payment, password request or document request fits a real business process unless someone in the organisation confirms the context.
- AI can miss a carefully crafted attack and can wrongly flag a legitimate message, so its classification cannot replace your IT or security process.
- Pasting a workplace email into an unapproved chatbot can expose confidential or personal information.
- AI cannot take responsibility for blocking the sender, reporting the incident or deciding whether an account or system needs investigation.
What caps this at PARTLY: real time truth, verification cost and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 1 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI tell if an email is phishing?
- It can assess supplied wording, sender details, headers and link text and point out suspicious indicators. It cannot prove that a message is safe or inspect live links and attachments, so a workplace IT or security colleague must make the final decision.
- Is it safe to paste a suspicious email into ChatGPT?
- Only use a chatbot approved by your employer and remove passwords, tokens and unnecessary personal or confidential information first. Do not paste sensitive workplace content into a public service if your organisation's policy does not allow it.
- What should I do if AI says an email is phishing?
- Do not click, reply, open an attachment or use a link in the message. Confirm the assessment through your organisation's IT or security process and report the email using the approved method.
- Can AI check email links?
- AI can compare visible link text with a destination you copy without opening it and explain common warning signs. It cannot safely establish the current contents or reputation of a live destination, so use your organisation's email security tools or ask IT to investigate it.
Nearby answers
- Can AI check whether my business passwords have been leaked?PARTLY
- Can AI check my business cybersecurity compliance with UK GDPR?NO
- Can AI choose a password manager for my business?YES
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI compare business antivirus software in the UK?PARTLY
- Can AI create a backup strategy for my small business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.