Eight checks. One clear verdict.

Every email is run through eight checks, each one flagged red, yellow or green — plus the SLURP habit that still works when no scanner is around.

EmailCheck.ai

Checks & verdict

Here's a pattern we catch every day — the tells marked on the left, how each check flagged it on the right.

The emailred marks = what EmailCheck flagged
Gmail
Search mail
D
Your account is limited
Inbox
A
Account Securityspoofed name

<security@acc0unt-secure.example> to me

9:41 AM

We detected unusual sign-in activity. Confirm access within 24 hours to keep the account active.

Verify my details

↳ actually points to http://91.203.0.14/verify

ReplyForward

Three seconds of reading says “my provider”. Five seconds of EmailCheck says three mismatched domains, a fake button and a manufactured deadline.

The verdict

Likely phishing
Red don't trust it
Yellow be careful
Green looks clean

The eight checks

what each found · how it's flagged

  • Sender authentication

    SPF, DKIM and DMARC all fail — nobody vouches for this sender

    Fail
  • Link safety

    “Verify my details” resolves to a raw IP address, not your provider

    Fail
  • Domain consistency

    Envelope, display and reply-to point to three different domains

    Fail
  • Typosquatting & homographs

    acc0unt-secure — a zero standing in for the letter o

    Fail
  • Display-name spoofing

    “Account Security” is not who the address says it is

    Fail
  • Header routing integrity

    Relayed through servers this brand has never mailed from

    Warning
  • Body & tracking pixels

    A hidden pixel reports back the moment you open the email

    Warning
  • Attachment safety

    No attachments — nothing to flag here

    Pass

How it works · Two modes · use AI to fight AI

Catch it. Then learn the tell.

Same scan, two readings. Analysis mode hands you the verdict in seconds. Teaching mode slows the same evidence down into a SLURP lesson — so the next scam doesn't need a scanner.

Analysis mode · the default

Scan & score

One tap on the open email. EmailCheck reads the authentication, links and routing, runs all eight checks and hands back the verdict — usually before you've finished the first paragraph.

Likely phishingscanned in 5s

Flagged red — sender authentication and link safety both failed.

Reach for it when you're about to click, reply, pay or forward — and you want the call, not a lecture.

Teaching mode · one switch away

Learn SLURP

The same scan, walked through out loud. EmailCheck takes the email in front of you through the five SLURP checks — the habit that still works when no scanner is around.

  • SSender authenticity — one character off, acc0unt reads as account
  • LLinks integrity — the link text and its real destination disagree
  • UUrgency pressure — a deadline is doing the persuading
  • RRequest reasonableness — the email asks for credentials, payment or access
  • PPretense and impersonation — a “verified” sender, but DKIM never signed it

Reach for it when you're training yourself or your team — the setting saves to your account and stays on until you switch back.

Need EmailCheck.ai?

Get EmailCheck