Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly spot a business email scam.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

30 minutesto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita colleague

What the alternative costsThe supplied tool data gives no price for a specialist email-security alternative.

If this goes wrong: you trust a fraudulent payment request or open a malicious link, and your organisation may lose money or expose its systems.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.

    How to actually do it

    1. Open the suspicious message without clicking its links, opening attachments or replying, and copy the body, sender address, reply-to address, visible links and attachment names.
    2. Use your mail application's message details or show-original function to copy the full headers if your organisation permits it, then remove passwords, access tokens and unnecessary personal data.
    3. Write down the normal business context, such as whether you expected the request, who normally authorises it and which payment or login process your organisation uses.
    4. Paste the redacted material and context into a chatbot with the supplied prompt, and ask it to distinguish observed facts from inferences.
    5. Check every claimed sender domain and destination domain by viewing the link text without opening it, and compare them with the organisation's known website or directory.
    6. Verify the request through a known internal contact or phone number from your existing records, not through contact details in the email.
    7. Send the email and the AI assessment to your IT or security team using your organisation's reporting process, and follow their decision before taking any requested action.

    Prompt

    Assess the business email below for signs of phishing, impersonation, malware delivery or payment fraud. Treat the assessment as a triage aid, not a final clearance. Do not open links, download attachments or contact the sender. Analyse the sender address, reply-to address, wording, urgency, requested action, payment or login instructions, domain names, visible URLs and any supplied mail headers. Separate facts quoted from the email from your inferences. Identify anything you cannot verify. Give me: 1) a risk rating of low, medium or high with a confidence level, 2) the specific warning signs, 3) benign explanations that remain possible, 4) safe verification steps using a known phone number, existing internal contact or independently typed website, 5) whether to report it to our IT or security team, and 6) a short action list stating what not to do. Never tell me to approve a payment, enter credentials or reply to the message based only on this analysis. Redact passwords, access tokens, personal data and confidential customer information before pasting. Business context: [describe the expected sender, request and normal process]. Email body: [paste the body]. Visible sender and recipient details: [paste them]. Reply-to address: [paste it, if shown]. Links and attachment names, without opening them: [paste them]. Full headers, if available: [paste them].

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot establish whether a sender's mailbox was compromised or whether a request matches a live internal transaction.
  • AI cannot safely verify a link, attachment or domain by interacting with it without creating additional security risk.
  • AI cannot replace your organisation's mail-security controls, threat intelligence or incident-response process.
  • AI cannot take responsibility for a payment, credential disclosure or malware infection caused by a wrong assessment.

What caps this at PARTLY: stakes of error, verification cost and real time truth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT tell if a business email is a scam?
It can triage the email and point out suspicious wording, sender details, links and requests. It cannot prove that the message is safe, so verify the request through a known internal contact and report it to IT or security before acting.
Should I paste a suspicious work email into AI?
Only use an organisation-approved tool and remove passwords, access tokens, personal data and confidential customer information first. Include the full headers if permitted, because the visible message alone may hide important clues.
Can AI check whether an invoice email is genuine?
It can identify signs of invoice fraud, such as a changed bank account, unusual urgency or a lookalike domain. Do not approve payment from that assessment; confirm the bank details and request through your established finance process.
What should I do if AI says an email is safe?
Treat that as a triage result, not clearance. Check the sender and destination independently, contact the supposed sender through a known route, and use your organisation's reporting process before opening attachments, entering credentials or paying.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.