Phishing and impersonation
Senders posing as your CEO, a supplier, a bank or Microsoft. Replies that go to a different address, look-alike domains, and requests to pay or change bank details.
Paste a suspicious email you received at work, headers and all. Aria, Intelligent Automation's AI assistant, checks it for phishing, fake sign-in pages, session theft, malware and spam, and tells you which links are dangerous. She never opens the links, and nothing you paste is kept.
Free and automated. Before You Click is a free, automated check for email you received at work. It is provided as-is, without warranty.
Business email only. If the message was delivered to a personal mailbox, such as Gmail, Outlook.com, Yahoo, iCloud or an internet provider's address, we decline to check it.
No personal or regulated information. The email must not contain PII, PHI, ePHI or ePII: no Social Security, card, bank or medical numbers, no dates of birth, no patient details, no passwords. The page blocks the common ones, but you are responsible for what you paste and for having the right to share it.
We do not collect your data. The email is held in memory only while the check runs, then discarded. We do not store it, we do not log what it says, and we never ask who you are.
Who else sees it. To produce the result, a trimmed copy of the email, with phone numbers, street addresses and your mailbox name replaced, is sent to our AI provider, Anthropic, which processes it under its commercial terms for API customers. The domains of its links are checked against threat-intelligence services. Full links and email addresses are not sent to those services.
We are not responsible for your data, or for what you do with the result. The result is an automated opinion and can be wrong. “Likely legitimate” does not mean an email is safe. When in doubt, ask your IT or security team.
Abuse protection. We keep a temporary counter so the tool cannot be overused. It holds no address and expires within a day.
Headers are required. They show who really sent the email and where it was delivered, which is how we confirm it is business email and the most reliable way to spot a fake.
Before You Click is not open yet. Please check back soon.
Analysis by Aria, Intelligent Automation's AI assistant. How we use AI.
Rule checks run first. Aria explains what they found and what they missed.
Senders posing as your CEO, a supplier, a bank or Microsoft. Replies that go to a different address, look-alike domains, and requests to pay or change bank details.
Links that show one address and go to another, brand names inside sites the brand does not own, and the free hosting services phishing kits favour.
The attacks a password reset does not fix: proxies that relay a real sign-in page and steal the session, app-consent links that ask for your mailbox, and device-code sign-in lures.
Attachments and downloads built to run code: disguised file types, disk images, OneNote files, macro documents and password-protected archives.
Unsolicited sales and bulk mail. Not dangerous, just unwanted, and labelled as such.
Each link's domain is checked against the same threat-intelligence sources as our URL & Email Checker. We never open or visit the link.
Before anything leaves your browser, the page looks for Social Security, card, bank and medical numbers, dates of birth and passwords. If it finds any, nothing is sent until they are removed, and our server checks again before Aria sees a word.
The email exists in memory for the few seconds the check takes. It is not stored and its contents are not logged. Attachments are stripped in your browser; we only look at their names and types.
Our rule checks and link reputation set a floor. Aria can raise the warning, never lower it, so an email written to fool an AI is still flagged.
We read where a link points and never visit it, so nothing in the email is triggered and the sender learns nothing about you.
Before You Click checks one message at a time. Intelligent Automation can protect every inbox in your company before the email arrives.