Fairfield, NJ · Metro New York (888) 711-4521 Founded 2013 · Metro New York
Aria Email Check

Before You Click. Ask Aria if that email is real.

Paste a suspicious email you received at work, headers and all. Aria, Intelligent Automation's AI assistant, checks it for phishing, fake sign-in pages, session theft, malware and spam, and tells you which links are dangerous. She never opens the links, and nothing you paste is kept.

  1. 1 Read and accept the terms

    Free and automated. Before You Click is a free, automated check for email you received at work. It is provided as-is, without warranty.

    Business email only. If the message was delivered to a personal mailbox, such as Gmail, Outlook.com, Yahoo, iCloud or an internet provider's address, we decline to check it.

    No personal or regulated information. The email must not contain PII, PHI, ePHI or ePII: no Social Security, card, bank or medical numbers, no dates of birth, no patient details, no passwords. The page blocks the common ones, but you are responsible for what you paste and for having the right to share it.

    We do not collect your data. The email is held in memory only while the check runs, then discarded. We do not store it, we do not log what it says, and we never ask who you are.

    Who else sees it. To produce the result, a trimmed copy of the email, with phone numbers, street addresses and your mailbox name replaced, is sent to our AI provider, Anthropic, which processes it under its commercial terms for API customers. The domains of its links are checked against threat-intelligence services. Full links and email addresses are not sent to those services.

    We are not responsible for your data, or for what you do with the result. The result is an automated opinion and can be wrong. “Likely legitimate” does not mean an email is safe. When in doubt, ask your IT or security team.

    Abuse protection. We keep a temporary counter so the tool cannot be overused. It holds no address and expires within a day.

  2. 2 Paste the email, headers included

    How to copy the full email from your mail app
    Outlook on the web, new Outlook, Microsoft 365
    Open the email, select More actions (…), then View and View message details (some versions say View message source). Select everything and copy it. If you only see headers, open “I only have the headers” below and paste the message text there.
    Classic Outlook for Windows
    Open the email in its own window, then File and Properties. Copy everything under Internet headers. Then open “I only have the headers” below and paste the message text there.
    Outlook for Mac (Microsoft 365)
    In the message list, Control-click (or right-click) the email and choose View Source. The whole email, headers and message text, opens in TextEdit or your default text editor. Press Command-A to select everything, then Command-C to copy it, and paste it here. This works in both the new and the classic Outlook for Mac.
    Gmail on Google Workspace
    Open the email, select the three dots next to Reply, then Show original and Copy to clipboard.
    Apple Mail
    Select the email, then View, Message, Raw Source. Select everything and copy it.
    Phones and tablets
    Most phone mail apps cannot show headers. Use a computer, or forward the email to your IT team.

    Headers are required. They show who really sent the email and where it was delivered, which is how we confirm it is business email and the most reliable way to spot a fake.

    I only have the headers. Add the message text.
  3. 3 Check it

    Analysis by Aria, Intelligent Automation's AI assistant. How we use AI.

What Aria looks for

Rule checks run first. Aria explains what they found and what they missed.

Phishing and impersonation

Senders posing as your CEO, a supplier, a bank or Microsoft. Replies that go to a different address, look-alike domains, and requests to pay or change bank details.

Fake sign-in pages

Links that show one address and go to another, brand names inside sites the brand does not own, and the free hosting services phishing kits favour.

Session and token theft

The attacks a password reset does not fix: proxies that relay a real sign-in page and steal the session, app-consent links that ask for your mailbox, and device-code sign-in lures.

Malware delivery

Attachments and downloads built to run code: disguised file types, disk images, OneNote files, macro documents and password-protected archives.

Spam

Unsolicited sales and bulk mail. Not dangerous, just unwanted, and labelled as such.

Link reputation

Each link's domain is checked against the same threat-intelligence sources as our URL & Email Checker. We never open or visit the link.

How your email is handled

Personal details stay out

Before anything leaves your browser, the page looks for Social Security, card, bank and medical numbers, dates of birth and passwords. If it finds any, nothing is sent until they are removed, and our server checks again before Aria sees a word.

Nothing is kept

The email exists in memory for the few seconds the check takes. It is not stored and its contents are not logged. Attachments are stripped in your browser; we only look at their names and types.

Aria cannot be talked out of a warning

Our rule checks and link reputation set a floor. Aria can raise the warning, never lower it, so an email written to fool an AI is still flagged.

Links are never opened

We read where a link points and never visit it, so nothing in the email is triggered and the sender learns nothing about you.

One email here. Every inbox with us.

Before You Click checks one message at a time. Intelligent Automation can protect every inbox in your company before the email arrives.

Secured by IA