PARTLY

As of 13 August 2026, AI can only partly detect phishing emails for your business.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

30 minutesto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita colleague

What the alternative costsNo price for a comparable alternative is supplied in the available tool data.

If this goes wrong: a genuine phishing message is treated as safe, and someone follows it before your business security controls or colleague intervene.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.

    How to actually do it

    1. Open the suspicious message in your business mail system without clicking its links, opening attachments or replying.
    2. Copy the subject, sender, reply-to address, visible body, attachment names and any available technical headers into a plain text document.
    3. Remove unnecessary personal information and confidential business content, then use an organisation-approved AI tool rather than pasting sensitive mail into an unapproved service.
    4. Paste the prepared details into the prompt and add the normal process or expected sender in the business-context field.
    5. Check the response against the original message, especially the sender and reply-to domains, urgency, payment or login request, link destinations and attachment details.
    6. Verify any proposed contact or payment request through a known company phone number, website or internal channel, not through the email.
    7. Send the message to your IT or security colleague with the AI assessment and original evidence, and follow the colleague's decision on reporting, blocking or deleting it.

    Prompt

    Assess the email below for phishing risk. Treat the result as triage, not a final security decision. Do not click links, open attachments or claim that a message is safe with certainty.
    
    Return:
    1. A risk rating of high, medium or low.
    2. A confidence level of high, medium or low.
    3. The specific evidence for the rating, including sender address, reply-to address, display name, linked domains, urgency, payment or credential requests, unusual wording, attachments and requests to bypass normal process.
    4. Any missing information that prevents a reliable assessment.
    5. Safe next actions for the recipient and for an administrator.
    6. Whether the message should be reported to the organisation's IT or security team.
    
    Use only the information supplied. Do not invent sender details, destinations or technical findings. If the message could be legitimate but cannot be confirmed, say that it needs independent verification. Do not ask the recipient to reply to the sender or use contact details in the message. Recommend checking through a known company channel instead.
    
    Business context: [briefly describe the normal process or expected sender, if known]
    Email subject: [paste subject]
    From: [paste sender address]
    Reply-to: [paste reply-to address, if shown]
    Date and time: [paste if relevant]
    Technical headers: [paste available headers after removing unnecessary personal data]
    Email body: [paste the message]
    Links shown in the email: [paste the visible link text and destination only if already available without opening the link]
    Attachments: [list names and types without opening them]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: stakes of error, verification cost and private data access.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can AI detect phishing emails?
Partly. AI can triage an email and point out suspicious sender details, links, requests and wording, but it cannot guarantee that a sophisticated message is safe.
Can I paste a suspicious email into ChatGPT?
Only if your business permits that tool and the message contains no data you are not allowed to share. Remove unnecessary personal and confidential information, do not click anything in the message, and send uncertain cases to your IT or security colleague.
How accurate is AI at spotting phishing emails?
There is no reliable accuracy figure for your particular inbox from a general chatbot. Treat its result as triage because compromised accounts, lookalike domains and well-written targeted attacks can defeat a text-only assessment.
What should I do if AI says an email is phishing?
Do not click, reply, pay or enter credentials through the message. Report it through your business process and verify any urgent request through a known internal or supplier channel.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.