PressedMail
Home
Features
Pricing
Sign InChoose a Pro plan
    • Overview
    • Phishing Reports
    • Links & Images
    • Lock & Impersonation
    • Where Mail Lives
Documentation

Phishing Detection and Reports

How PressedMail scores a suspicious message, which signals it weighs, and what the safety report actually shows you.

A verdict you cannot inspect is just a vibe. This page covers how a message gets scored, what the report puts in front of you, and when any of it runs.

The passes, in order

Each analysis walks the same sequence, and each pass returns its own status of safe, warning, danger, or skipped.

  1. Sender and identity. Domain and display name, checked against a lookalike map.
  2. Body and language. Urgency, payment pressure, credential requests.
  3. Authentication headers. SPF, DKIM, DMARC, and routing. Skipped when no message UID is passed or the headers cannot be fetched over IMAP.
  4. Link inspection. Every link and inline image, plus how far their domains sit from the sender's.
  5. Attachments and downloads. Filename, extension, and declared MIME type.
  6. Prompt injection and hidden content. Twelve checks, run before any body text is sent anywhere.
  7. Identity and intent coherence. Does the claimed organisation match the sender, the destinations, and the thing being asked for.
  8. AI verdict. The configured model reviews the evidence the first seven passes gathered.

If the AI step fails or the provider is unreachable, the report still arrives, marked as based on the direct checks only.

The thirteen signals

Findings are classified into thirteen named types: typosquatting, name mismatch, suspicious subject, known pattern, authentication failure, suspicious link, image mismatch, header mismatch, reply-to mismatch, hidden text, prompt injection, body social engineering, and suspicious attachment. Anything the model returns outside that list is dropped.

The hidden-content pass covers twelve specific tricks: hidden HTML text, white-on-white text, display:none text, visibility:hidden text, opacity:0 text, zero or tiny font sizes, off-screen positioning, text colour matching the background, text stacked behind other elements, instructions buried in HTML comments, RTF hidden text, and prompt-injection phrases.

How the score lands

Heuristic findings accumulate into a score capped at 100. The final score is whichever is higher, the heuristics or the model. Two guardrails push it up rather than down: if the model calls the message suspicious the score is floored at 31, and two or more high-severity findings floor it at 60. The model cannot talk a message back down.

Verdicts follow the score. 1 to 30 is safe, 31 to 60 is caution, 61 to 100 is danger. The safety rating you see on the report is simply 100 minus the risk score.

What the report shows

The Phishing Safety Report opens over the message. At the top: the safety rating out of 100, a plain summary, and a recommended action. Below that, six evidence cards, one per pass, each listing the findings behind its status. Expand the technical details for the raw risk score, the verdict string, and when the cached result expires.

When it runs

Phishing analysis is off until an administrator configures a provider and turns it on. The site policy then decides who scans what:

  • Allow. The reading pane shows a check button. Analysis is manual only.
  • Force. Every opened message is analysed automatically.
  • Disable. Nothing runs, and the button disappears.

Queued scans process five messages per run rather than one API call per message. Results are cached for seven days per message. Nothing is auto-tagged; a suspicious message is surfaced through the indicator and the report, not by writing a label into your mailbox.

Free and paid

Phishing detection is a paid feature. The service is excluded from the Free build entirely, so it is absent rather than disabled.

Read Next

  • Link Analysis and Remote Images
  • Where Your Mail Lives
  • Security and Privacy Intro
Previous

Security and Privacy Overview

Understand the PressedMail security model before configuring provider accounts, roles, diagnostics, or AI.

Next

Link Analysis and Remote Images

What PressedMail checks before you click a link, and why remote images stay dark until you say otherwise.

© 2026 PressedMail. All rights reserved.
DocsSupportTermsPrivacyRefunds
PressedMail

A WordPress-Native Email Workspace. Connect your existing email accounts and manage messages, contacts, and calendar from your WordPress dashboard.

Product

  • Features
  • Pricing

Resources

  • Docs
  • Changelog
  • Roadmap

About

  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy

© 2026 PressedMail. A product of CurbSoftware Tech Innovations.

PressedMail processes email on your WordPress site and connects directly to your email provider. CurbSoftware’s OAuth relay does not receive message bodies or attachments.