Use cases

Tell which reported phishing emails are real

Reads each email staff report for what it wants, who it fakes and whether the reporter clicked. Text only: your mail tools still check links and files.

Try it on this example

Example · A payroll login phish, and the reporter already typed a password

Reported email's subject: Action required: payroll portal migration - confirm by 5pm

Sender display name and address: HR Payroll Team <[email protected]>

What the reporter wrote (empty if nothing): Looked odd but I had already clicked and typed my password before I noticed the address. Sorry!

Email body as text, each link shown with its domain

Dear colleague, As part of our move to a new payroll provider, all staff must re-confirm their network login before 5pm today. Staff who do not confirm in time may see next month's salary delayed. Please sign in with your usual network username and password here: Confirm my account [kestrel-hrportal.example] This is an automated message. Please do not reply, and do not contact the service desk about it, as they are not involved in the migration. Kind regards, HR Operations Kestrel Components
  1. What kind of email is this, judged from its text?Credential phishing100%
  2. Does the email present itself as coming from our own staff, executives, IT, HR or payroll, from an address that is not ours?Yes94%
  3. Does the email present itself as coming from a known outside service, bank, courier or supplier, from an address that does not belong to it?No79%
  4. Does the email ask the reader to enter or send a password, a one-time code or login details?Yes99%
  5. Does the email ask for a payment, gift cards, or a change to bank or payment details?No93%
  6. Does the email push the reader to act fast or warn of a loss if they do not?Yes99%
  7. Does the email ask the reader to keep it secret, not to check with anyone, or to move to a personal phone or chat app?Yes96%
  8. Does the reporter say they acted on the email before reporting it?Acted on it100%
  9. How much harm could this email do if a reader acted on it?High100%
  10. Is there enough text in the reported email to judge it?Yes98%

These are real answers stored from one run on this example.

The prism behind it

Tell which reported phishing emails are real10 questions

Fields

  • Reported email's subject
  • Sender display name and address
  • Email body as text, each link shown with its domain
  • What the reporter wrote (empty if nothing)

Context

We are Kestrel Components, a manufacturer with about 3,500 staff. Our own email domain is kestrelcomponents.example. Staff press Report phishing in Outlook, and each reported email arrives here with the note the reporter wrote, if any. The body is plain text, and each link shows its visible text followed by its real domain in brackets. Services that legitimately email our staff: Paystream for payroll and payslips (paystream.example), PeopleHub, our HR system (peoplehub.example), Wayfare for business travel (wayfare.example), Microsoft 365 notifications, and DocuSign for contracts. Our rules: - IT, HR and payroll never ask for a password or a one-time code by email. - Finance never pays or changes supplier bank details on an email request alone. - Executives never ask staff to buy gift cards. What these answers are for: they read the text only. Link, attachment and header checks run in our mail security tools, and code combines those results with these answers. A report is closed as harmless only when those tools also find nothing; a security analyst reviews everything else. Simulated phishing tests are recognised by their header in code and never reach this step.

Questions

  1. What kind of email is this, judged from its text? Choice

    Judge what the email is trying to get the reader to do, using the sender, the subject and the body. When it does more than one thing, pick the one that would do the most harm if the reader acted on it. Do not judge links or attachments beyond what the text says about them.

    • Credential phishing Asks the reader to sign in, confirm an account, or enter a password or code, through a link or a form.
    • Malware delivery Pushes the reader to open an attachment, enable editing or macros, or download and run a file.
    • Payment fraud Asks for a payment, gift cards, a transfer or a change of bank details, often posing as an executive or a supplier.
    • Call-back scam Asks the reader to phone a number, usually about a charge, a renewal or an order they did not make.
    • Extortion or scare Threatens to expose the reader, or claims a hack, to demand money.
    • Spam or marketing An unwanted promotion or a newsletter, with no deceptive request of the reader.
    • Legitimate A genuine internal, customer, supplier or service email, including the services listed in the context.
  2. Does the email present itself as coming from our own staff, executives, IT, HR or payroll, from an address that is not ours? Yes / No

    Compare the display name, the signature and the wording with the sender address and our domain in the context. A genuine address on our own domain is No; header checks in code catch spoofing. Yes: The email presents itself as internal, and the sender address is not on our domain. No: The email does not present itself as internal, or it comes from our own domain.

  3. Does the email present itself as coming from a known outside service, bank, courier or supplier, from an address that does not belong to it? Yes / No

    For the services listed in the context, compare the sender with the domain given there. For other brands, judge whether the address plausibly belongs to the brand named. An email that presents itself as our own staff or departments belongs to the question on colleagues; answer Yes here only when an outside organisation is named or branded. Yes: The email names or brands itself as an outside organisation, and the sender address does not fit that organisation. No: The email names no outside organisation, or the sender fits the one it names.

  4. Does the email ask the reader to enter or send a password, a one-time code or login details? Yes / No

    Count a request by link, form, attachment or reply, in any words, such as "confirm your login" or "re-validate your mailbox". Yes: The email asks for a password, a code or login details, or sends the reader to a page to enter them. No: No such request appears.

  5. Does the email ask for a payment, gift cards, or a change to bank or payment details? Yes / No

    Count a request to pay, transfer, buy gift cards or vouchers, or change where money is sent, for the company or for the reader. Yes: The email asks for any of these. No: No such request appears. A mention of salary or an invoice with no request to pay or change details is No.

  6. Does the email push the reader to act fast or warn of a loss if they do not? Yes / No

    Count a deadline, "today only", "urgent", or a warning that an account will close, pay will be delayed or a penalty will apply. Yes: The email creates time pressure or threatens a loss. No: No such pressure appears.

  7. Does the email ask the reader to keep it secret, not to check with anyone, or to move to a personal phone or chat app? Yes / No

    Count "keep this between us", "do not contact the service desk", "do not call me, I am in meetings", or a request to continue by text, WhatsApp or a personal email. Yes: The email asks for secrecy, discourages checking through normal channels, or moves the conversation elsewhere. No: No such request appears. A standard "do not reply to this automated message" with nothing more is No.

  8. Does the reporter say they acted on the email before reporting it? Choice

    Read only the reporter's note, not the reported email.

    • Acted on it The note says the reporter clicked a link, opened an attachment, entered details, replied, called the number or paid.
    • Did not say they acted The note says the reporter did not act on the email, or says nothing either way.
    • No note The reporter note field is empty.
  9. How much harm could this email do if a reader acted on it? Scale

    Judge the harm from the request the email makes, as its text shows it. Do not lower the level because the reporter did not act.

    • None A legitimate or harmless email.
    • Low A nuisance, such as spam or a newsletter, with no deceptive request.
    • Medium Suspicious, such as an unexpected sender or a vague story, but with no clear request for credentials, money or a file.
    • High A clear deceptive request for credentials, money, a call or a file.
  10. Is there enough text in the reported email to judge it? Yes / No

    Answer No when the body is empty, holds only an attachment name or an image placeholder, or is too garbled to read. Yes: The subject and body give a careful reader enough to judge what the email wants. No: The text is too thin to judge; the attachment or image carries the content.

Lens columns

verdict, verdict_probability, poses_as_colleague, poses_as_colleague_probability, poses_as_known_service, poses_as_known_service_probability, requests_credentials, requests_credentials_probability, requests_payment_or_bank_change, requests_payment_or_bank_change_probability, pressure, pressure_probability, asks_secrecy_or_bypass, asks_secrecy_or_bypass_probability, reporter_action, reporter_action_probability, risk, risk_average, enough_to_judge, enough_to_judge_probability

Run it on your own text

Add this prism in the app, change any question, and test it on a file of your own.

Ask for an invite