Know if that email is actually from your bank.

Phishing emails are getting smarter. CatPhish gives you the tools a security analyst uses to investigate them—in seconds, for free.

Case #0234
From: "Chase Bank" <secure-verify@chase-alert.com>
Subject: Urgent: Verify your account
Checks:
SPF: Failed (real Chase uses SPF)
Sender IP: Not Chase's network
Domain: chase-alert.com (not chase.com)
Link target: Known phishing site
Verdict: MALICIOUS
Risk score: 89/100

Three things we check that most people miss.

Every phishing email has tells. We automate what security analysts do manually.

What you actually get.

A real risk score.

Not "this might be phishing" — a 0–100 score with every finding explained. You can understand exactly why an email flagged.

An exportable report.

Markdown or JSON. Defanged links (hxxp instead of http). Everything formatted for your IT team, your bank's fraud line, or Canada's anti-fraud centre.

Works offline or online.

Your email never leaves your device if you don't want it to. Run heuristics-only (no internet), or let us check against live threat databases.

Handles SMS too.

Smishing emails (text message phishing) are on the rise. Same analysis, different signals.

Built for the moment you're not sure.

"Is this really my bank?"
The logo is right, the wording is close, the link looks almost correct. Paste it in and find out which of those three is lying.
"My mum forwarded me this."
You're the family's tech support. Run it, export the report, and send back something more convincing than "looks fake to me."
"An invoice arrived from a supplier."
Same sender name, new bank details. Header authentication and domain age answer that faster than a phone call does.

Your email isn't our data.

We analyse the message, store only the verdict and metadata, and discard the body. No emails are kept on our servers. Sign-in is Google-only (we never see your password).

Questions people ask.

How do I get the raw email?
Gmail: Open the email → ⋮ (menu) → "Show original" → copy everything.
Outlook: Open the email → ⋯ (menu) → "View" → "View message source" → copy everything.
Paste it into our scanner. That's it.
Do you actually check against threat intel?
Yes. We use VirusTotal (free tier), AbuseIPDB, URLhaus, and RDAP for domain age. All lookups are optional—run fully offline if you prefer.
What if I just want heuristics?
Check the "offline" box. We'll still catch typosquats, homoglyphs, suspicious TLDs, and auth failures. No internet calls needed.
Do you actually open the links?
Yes — in a throwaway headless browser on our server, never in your browser. You get a screenshot of the page, where the link really ended up, and whether it's asking for a password. That's the part you'd otherwise have to risk clicking to find out. Tick "offline" if you'd rather we didn't: opening a link tells the sender their message was read.
What doesn't it do?
We don't open attachments or run them. We don't do full behavioural malware analysis — for that, use Any.run or Joe Sandbox. And a clean verdict isn't a guarantee; it means nothing we check for showed up.
How is this different from my email provider's spam filter?
Your email provider catches obvious spam. We catch sophisticated phishing that already landed in your inbox—things that look legitimate but aren't. Your provider says "blocked." We say "why."

The next suspicious email doesn't have to be a guess.

Free account, no card.

Get started →