Phishing Analyzer
Before you submit
- Only paste the text of the message. Do not include passwords, one-time codes, or other credentials.
- Your submission is used to produce this result and is not stored afterward.
- Results combine automatic pattern detection with an optional AI-generated explanation. Automatic detection always determines the risk score, risk level, and indicators shown below -- the explanation, when available, is supplementary context only.
- This tool is a decision aid, not a guarantee. Always verify unexpected or urgent requests through a separate, trusted channel.
Example result
Illustrative example, not a live analysisHere is what CyberBlink returns for a sample message engineered to contain every one of the ten patterns this engine detects. The sample message:
Subject: Account Verification Required · From: PayPal Security Team
URGENT: Your account will be suspended within 24 hours due to unusual activity. Dear Customer, please verify your password immediately by clicking the link below: http://bit.ly/paypal-verify. You will also need to confirm your account credentials and provide your social security number and credit card number for identity verification. Outstanding invoice INV-4471 remains unpaid -- failure to respond may result in legal action and your acc0unt being permanently deleted. Verify now to claim your reward and avoid further penalty.
This is the exact production result component a real analysis uses, rendering this fixed sample message's actual computed output -- not a live analysis:
Analysis result
Critical risk · 100/100Likely attack: Payment / Invoice Fraud
This message requests your password or account credentials, asks for sensitive personal or financial information, and directs you to a suspicious link.
Why CyberBlink flagged this
Credential request (High severity)
“…unusual activity. dear customer, please verify your password immediately by clicking the link below:…”
Asks the reader to verify, confirm, or re-enter a password or account credentials via a link.
Message body
Sensitive data request (High severity)
“…ur account credentials and provide your social security number and credit card number for identity ver…”
Requests highly sensitive personal or financial data such as a card number, PIN, or verification code.
Message body
Suspicious shortened link (High severity)
http://bit.ly/paypal-verify.
Uses a link-shortening service that hides the real destination until clicked.
Link URL
What should I do?
Verify payment or account changes independently
Do not act on payment, invoice, or account-detail changes from this message. Confirm them using a known, trusted contact method -- not the reply-to address or phone number in the message.
View technical details
All findings
Credential request
High severityAsks the reader to verify, confirm, or re-enter a password or account credentials via a link.
- Message body:“…unusual activity. dear customer, please verify your password immediately by clicking the link below:…”
- 1 additional related match
Sensitive data request
High severityRequests highly sensitive personal or financial data such as a card number, PIN, or verification code.
- Message body:“…ur account credentials and provide your social security number and credit card number for identity ver…”
- 1 additional related match
Suspicious link
High severityContains a link shortener, a raw IP-address link, or a punycode (internationalized) domain.
- Link URL:“…immediately by clicking the link below: http://bit.ly/paypal-verify. you will also need to confirm your acco…”
Possible brand impersonation
High severityNames a well-known brand alongside words like "security" or "support", a common impersonation pattern.
- Link URL:“…clicking the link below: http://bit.ly/paypal-verify. you will also need to confirm your acc…”
- 1 additional related match
Urgency language
Medium severityUses time pressure or urgent phrasing to rush a decision (e.g. "act now", "within 24 hours").
- Message body:“urgent: your account will be suspended within…”
- 2 additional related matches
Financial lure
Medium severityPromises an unexpected prize, refund, or windfall to entice a response.
- Message body:“…eing permanently deleted. verify now to claim your reward and avoid further penalty.”
Payment or invoice action request
Medium severityAsks the reader to review, confirm, or complete a payment or invoice. Common in legitimate billing too -- only a stronger signal when combined with urgency or a threatened consequence.
- Message body:“…for identity verification. outstanding invoice inv-4471 remains unpaid -- failure to respond may result in leg…”
- 1 additional related match
Threat of consequence
Medium severityThreatens a negative consequence, such as legal action or account termination, for inaction.
- Message body:“…ding invoice inv-4471 remains unpaid -- failure to respond may result in legal action and your acc…”
- 2 additional related matches
Generic greeting
Low severityUses an impersonal greeting (e.g. "Dear Customer") instead of the reader's name.
- Message body:“…ithin 24 hours due to unusual activity. dear customer, please verify your password immediatel…”
Obfuscated wording
Low severityUses character substitution (e.g. "p4ssword") sometimes used to evade simple keyword filters.
- Message body:“…ond may result in legal action and your acc0unt being permanently deleted. verify now t…”
All suspicious links
http://bit.ly/paypal-verify.
- Uses a link-shortening service that hides the real destination until clicked.
Attack pattern
Urgency language, credential request, sensitive data request, suspicious link, generic greeting, financial lure, payment or invoice action request, threat of consequence, possible brand impersonation, and obfuscated wording together are consistent with payment or invoice fraud.
All recommended actions
Report and delete immediately
This message shows a high concentration of phishing indicators. Do not interact with it. Report it and delete it immediately.
Never enter credentials from a link
Do not use the link in this message, and never enter your password through it. Open the service through a known, trusted app or bookmark instead. If you already entered credentials, change them through the official service and follow your organization's incident-response process.
Avoid clicking links in this message
Avoid clicking any links in this message. Inspect links before trusting them, or navigate directly to the known official site instead.
Verify payment or account changes independently
Do not act on payment, invoice, or account-detail changes from this message. Confirm them using a known, trusted contact method -- not the reply-to address or phone number in the message.
Verify through an official channel
If this claims to be from a known company, contact that company directly using contact information from their official website, not from this message.
Limitations: This tool automatically detects known phishing patterns. It is a decision aid, not a guarantee of safety or danger, and it can miss novel or highly targeted messages. Always verify unexpected or urgent requests through a separate, trusted channel before acting on them.
How this works
CyberBlink checks every submitted message against 10 deterministic patterns, each independently weighted into the overall risk score:
- Urgency language: Uses time pressure or urgent phrasing to rush a decision (e.g. "act now", "within 24 hours").
- Credential request: Asks the reader to verify, confirm, or re-enter a password or account credentials via a link.
- Sensitive data request: Requests highly sensitive personal or financial data such as a card number, PIN, or verification code.
- Suspicious link: Contains a link shortener, a raw IP-address link, or a punycode (internationalized) domain.
- Generic greeting: Uses an impersonal greeting (e.g. "Dear Customer") instead of the reader's name.
- Financial lure: Promises an unexpected prize, refund, or windfall to entice a response.
- Payment or invoice action request: Asks the reader to review, confirm, or complete a payment or invoice. Common in legitimate billing too -- only a stronger signal when combined with urgency or a threatened consequence.
- Threat of consequence: Threatens a negative consequence, such as legal action or account termination, for inaction.
- Possible brand impersonation: Names a well-known brand alongside words like "security" or "support", a common impersonation pattern.
- Obfuscated wording: Uses character substitution (e.g. "p4ssword") sometimes used to evade simple keyword filters.
Any URL found in the message is also checked for link-shortener use, raw IP-address links, punycode (internationalized) domains, and embedded “user:pass@” credential syntax -- never fetched, rendered, or followed.
Submit a message for analysis
Paste the text of a suspicious email or message below. Only the text you enter here is analyzed, and it is not stored after your results are shown.