Tell which reported phishing emails are real
Reads each email staff report for what it wants, who it fakes and whether the reporter clicked. Text only: your mail tools still check links and files.
Try it on this example
Reported email's subject: Action required: payroll portal migration - confirm by 5pm
Sender display name and address: HR Payroll Team <[email protected]>
What the reporter wrote (empty if nothing): Looked odd but I had already clicked and typed my password before I noticed the address. Sorry!
Email body as text, each link shown with its domain
- What kind of email is this, judged from its text?Credential phishing100%
- Does the email present itself as coming from our own staff, executives, IT, HR or payroll, from an address that is not ours?Yes94%
- Does the email present itself as coming from a known outside service, bank, courier or supplier, from an address that does not belong to it?No79%
- Does the email ask the reader to enter or send a password, a one-time code or login details?Yes99%
- Does the email ask for a payment, gift cards, or a change to bank or payment details?No93%
- Does the email push the reader to act fast or warn of a loss if they do not?Yes99%
- Does the email ask the reader to keep it secret, not to check with anyone, or to move to a personal phone or chat app?Yes96%
- Does the reporter say they acted on the email before reporting it?Acted on it100%
- How much harm could this email do if a reader acted on it?High100%
- Is there enough text in the reported email to judge it?Yes98%
These are real answers stored from one run on this example.
The prism behind it
Tell which reported phishing emails are real
Fields
- Reported email's subject
- Sender display name and address
- Email body as text, each link shown with its domain
- What the reporter wrote (empty if nothing)
Context
We are Kestrel Components, a manufacturer with about 3,500 staff. Our own email domain is kestrelcomponents.example. Staff press Report phishing in Outlook, and each reported email arrives here with the note the reporter wrote, if any. The body is plain text, and each link shows its visible text followed by its real domain in brackets. Services that legitimately email our staff: Paystream for payroll and payslips (paystream.example), PeopleHub, our HR system (peoplehub.example), Wayfare for business travel (wayfare.example), Microsoft 365 notifications, and DocuSign for contracts. Our rules: - IT, HR and payroll never ask for a password or a one-time code by email. - Finance never pays or changes supplier bank details on an email request alone. - Executives never ask staff to buy gift cards. What these answers are for: they read the text only. Link, attachment and header checks run in our mail security tools, and code combines those results with these answers. A report is closed as harmless only when those tools also find nothing; a security analyst reviews everything else. Simulated phishing tests are recognised by their header in code and never reach this step.
Questions
What kind of email is this, judged from its text? Choice
Judge what the email is trying to get the reader to do, using the sender, the subject and the body. When it does more than one thing, pick the one that would do the most harm if the reader acted on it. Do not judge links or attachments beyond what the text says about them.
Does the email present itself as coming from our own staff, executives, IT, HR or payroll, from an address that is not ours? Yes / No
Compare the display name, the signature and the wording with the sender address and our domain in the context. A genuine address on our own domain is No; header checks in code catch spoofing. Yes: The email presents itself as internal, and the sender address is not on our domain. No: The email does not present itself as internal, or it comes from our own domain.
Does the email present itself as coming from a known outside service, bank, courier or supplier, from an address that does not belong to it? Yes / No
For the services listed in the context, compare the sender with the domain given there. For other brands, judge whether the address plausibly belongs to the brand named. An email that presents itself as our own staff or departments belongs to the question on colleagues; answer Yes here only when an outside organisation is named or branded. Yes: The email names or brands itself as an outside organisation, and the sender address does not fit that organisation. No: The email names no outside organisation, or the sender fits the one it names.
Does the email ask the reader to enter or send a password, a one-time code or login details? Yes / No
Count a request by link, form, attachment or reply, in any words, such as "confirm your login" or "re-validate your mailbox". Yes: The email asks for a password, a code or login details, or sends the reader to a page to enter them. No: No such request appears.
Does the email ask for a payment, gift cards, or a change to bank or payment details? Yes / No
Count a request to pay, transfer, buy gift cards or vouchers, or change where money is sent, for the company or for the reader. Yes: The email asks for any of these. No: No such request appears. A mention of salary or an invoice with no request to pay or change details is No.
Does the email push the reader to act fast or warn of a loss if they do not? Yes / No
Count a deadline, "today only", "urgent", or a warning that an account will close, pay will be delayed or a penalty will apply. Yes: The email creates time pressure or threatens a loss. No: No such pressure appears.
Does the email ask the reader to keep it secret, not to check with anyone, or to move to a personal phone or chat app? Yes / No
Count "keep this between us", "do not contact the service desk", "do not call me, I am in meetings", or a request to continue by text, WhatsApp or a personal email. Yes: The email asks for secrecy, discourages checking through normal channels, or moves the conversation elsewhere. No: No such request appears. A standard "do not reply to this automated message" with nothing more is No.
Does the reporter say they acted on the email before reporting it? Choice
Read only the reporter's note, not the reported email.
How much harm could this email do if a reader acted on it? Scale
Judge the harm from the request the email makes, as its text shows it. Do not lower the level because the reporter did not act.
Is there enough text in the reported email to judge it? Yes / No
Answer No when the body is empty, holds only an attachment name or an image placeholder, or is too garbled to read. Yes: The subject and body give a careful reader enough to judge what the email wants. No: The text is too thin to judge; the attachment or image carries the content.
Lens columns
verdict, verdict_probability, poses_as_colleague, poses_as_colleague_probability, poses_as_known_service, poses_as_known_service_probability, requests_credentials, requests_credentials_probability, requests_payment_or_bank_change, requests_payment_or_bank_change_probability, pressure, pressure_probability, asks_secrecy_or_bypass, asks_secrecy_or_bypass_probability, reporter_action, reporter_action_probability, risk, risk_average, enough_to_judge, enough_to_judge_probability
Run it on your own text
Add this prism in the app, change any question, and test it on a file of your own.