5 items
AI-powered phishing triage. Analyze suspicious emails and web pages instantly. **PhishTriage tells you whether the thing in front of you is a phishing attempt.** Open the suspicious email, or the login page that feels wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next. ### It reads nothing until you ask On an ordinary web page the extension holds no standing access. It reads the page under `activeTab`, which exists only in the moment you click. One exception, and your browser shows it at install: on Gmail and Outlook Web (`mail.google.com`, `outlook.office.com`, `outlook.office365.com`, `outlook.live.com`) a content script is present from the start, because that is how the Analyze button reaches the mail toolbar. Nothing else is touched unless you switch on an optional feature below. From an email it sends the subject; the sender, recipient and reply-to addresses; the body, with quoted threads and signatures stripped; the links; and attachment filenames, not attachment contents. Who a message claims to be from is the strongest single signal there is. From any other page: the title, the visible text, the links, and the full address including path and query. ### When it is phishing, the page can come down A verdict argues; an artifact proves. When a web page you analyze comes back Malicious or Suspicious, a screenshot of the visible tab and that page's HTML go up with it, so the site can be reported to its host or registrar. **This is the one setting here that starts on:** setup shows it, and the switch is in the popup. Nothing is captured on a benign verdict, and nothing on Gmail or Outlook Web, where the screenshot would be of your inbox. Webmail on any other host counts as an ordinary page, and there the picture is of your inbox — the privacy policy names the providers this affects. Both are held in memory for the seconds the scan takes, never written to your disk. Confirmed malicious is kept 12 months, suspicious 30 days, and a capture a reviewer clears is deleted at once. ### Optional, and off until you switch them on **Background protection** checks each site as it loads and shows a full-page warning if it is known bad. Your browser asks permission first; decline, or revoke later. Only the hostname is sent, not the page you are on. Separate switches send full URLs instead, and cache a site for an hour; both off. **File protection** (Chrome, Edge, Brave) checks your downloads. A fingerprint goes up with the file's name, its size, and what the on-device check made of it; the file itself only when you ask for that one file, or on every download if you switch on *Deep scan every file*. Another switch holds files a page builds in your browser and asks before they save, instead of warning after. For an ordinary download the extension fetches the file's address a second time — a browser hands an extension a download's details, not its contents — and that request carries your cookies as the first did. ### What it does not do No third-party analytics, advertising or telemetry. No identity permission: it never asks your browser or your mail provider who you are. Your install is identified by a random id, replaced at registration by one our server issues; it registers once at install, sending that id, your browser name, and an enrolment token if an administrator set one. The feedback buttons under a verdict record your correction on your own device and send nothing. ### Teams Sign in from the popup and the portal opens to finish the link. An administrator links the device to your organisation there; the extension never takes a credential. For a fleet, push an enrolment token by managed policy and devices join at install. Policy also pins the backend and sets the monitoring, file-protection, deep-scan and evidence switches for everyone, in either direction, so on a managed device a switch may already be on, or held off.
Aug 25, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.