Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly spot a business email scam.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
30 minutesto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita colleague
What the alternative costsThe supplied tool data gives no price for a specialist email-security alternative.
If this goes wrong: you trust a fraudulent payment request or open a malicious link, and your organisation may lose money or expose its systems.
What to actually do
Hand it to a person
The route this page recommends
A person who owns the outcome does this end to end, worth it when the failure is dear.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.
How to actually do it
- Open the suspicious message without clicking its links, opening attachments or replying, and copy the body, sender address, reply-to address, visible links and attachment names.
- Use your mail application's message details or show-original function to copy the full headers if your organisation permits it, then remove passwords, access tokens and unnecessary personal data.
- Write down the normal business context, such as whether you expected the request, who normally authorises it and which payment or login process your organisation uses.
- Paste the redacted material and context into a chatbot with the supplied prompt, and ask it to distinguish observed facts from inferences.
- Check every claimed sender domain and destination domain by viewing the link text without opening it, and compare them with the organisation's known website or directory.
- Verify the request through a known internal contact or phone number from your existing records, not through contact details in the email.
- Send the email and the AI assessment to your IT or security team using your organisation's reporting process, and follow their decision before taking any requested action.
Prompt
Assess the business email below for signs of phishing, impersonation, malware delivery or payment fraud. Treat the assessment as a triage aid, not a final clearance. Do not open links, download attachments or contact the sender. Analyse the sender address, reply-to address, wording, urgency, requested action, payment or login instructions, domain names, visible URLs and any supplied mail headers. Separate facts quoted from the email from your inferences. Identify anything you cannot verify. Give me: 1) a risk rating of low, medium or high with a confidence level, 2) the specific warning signs, 3) benign explanations that remain possible, 4) safe verification steps using a known phone number, existing internal contact or independently typed website, 5) whether to report it to our IT or security team, and 6) a short action list stating what not to do. Never tell me to approve a payment, enter credentials or reply to the message based only on this analysis. Redact passwords, access tokens, personal data and confidential customer information before pasting. Business context: [describe the expected sender, request and normal process]. Email body: [paste the body]. Visible sender and recipient details: [paste them]. Reply-to address: [paste it, if shown]. Links and attachment names, without opening them: [paste them]. Full headers, if available: [paste them].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot establish whether a sender's mailbox was compromised or whether a request matches a live internal transaction.
- AI cannot safely verify a link, attachment or domain by interacting with it without creating additional security risk.
- AI cannot replace your organisation's mail-security controls, threat intelligence or incident-response process.
- AI cannot take responsibility for a payment, credential disclosure or malware infection caused by a wrong assessment.
What caps this at PARTLY: stakes of error, verification cost and real time truth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT tell if a business email is a scam?
- It can triage the email and point out suspicious wording, sender details, links and requests. It cannot prove that the message is safe, so verify the request through a known internal contact and report it to IT or security before acting.
- Should I paste a suspicious work email into AI?
- Only use an organisation-approved tool and remove passwords, access tokens, personal data and confidential customer information first. Include the full headers if permitted, because the visible message alone may hide important clues.
- Can AI check whether an invoice email is genuine?
- It can identify signs of invoice fraud, such as a changed bank account, unusual urgency or a lookalike domain. Do not approve payment from that assessment; confirm the bank details and request through your established finance process.
- What should I do if AI says an email is safe?
- Treat that as a triage result, not clearance. Check the sender and destination independently, contact the supposed sender through a known route, and use your organisation's reporting process before opening attachments, entering credentials or paying.
Nearby answers
- Can AI check my business cybersecurity compliance with UK GDPR?NO
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI detect a data breach in my business?NO
- Can AI identify cybersecurity risks in my small business?PARTLY
- Can AI help my business respond to a ransomware attack?PARTLY
- Can AI help me choose and secure a VPN for my business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.