Trust and control

Security & Phishing

See why a message looks suspicious, block hidden tracking, and keep unsafe email code away from the page.

Product Tour
A suspicious message scored and its report opened
03 · 01

See it work

  • Phishing review
  • Link analysis
  • Remote images blocked
  • Mailbox lock
0Links checked
0Flagged
0Direct fetches

Incident inspection

Illustrative suspicious message

Review before opening

Your account needs verification

14 Jul

PayPal Security <[email protected]>

We could not verify a recent payment. Confirm your details at paypal.com within 24 hours or your account will be limited.

1 remote image blocked

Tracking pixel, not requested

3 flagged

Link warnings run locally. The full phishing verdict uses the AI provider you configure.

Phishing Safety Report

Illustrative AI-assisted verdict

Likely phishing

Safety rating

34/ 100

Do not sign in from this message. Open the account yourself if you want to check it.

Key signals

Lookalike senderLookalike linkText vs destination
  • Sender and identityFail

    [email protected] does not match paypal.com

  • AuthenticationWarning

    SPF, DKIM and DMARC pass for paypa1.example

  • Links and destinationsFail

    3 of 4 links carry signals

  • Body and languageWarning

    Urgent deadline: within 24 hours

  • Hidden contentPass

    No prompt injection or hidden markup

  • AttachmentsInfo

    No attachments on this message

Authentication proves who owns a domain, not who it claims to be. The full verdict uses the AI provider you configure.

Sanitized before rendering

What remains renders in a sandboxed iframe under a strict content security policy.

Removed server-side

<script><iframe><object><embed><applet><form><svg>

Allowed link protocols

httphttpsmailtotelcid
Capabilities

Everything Security & Phishing covers

7 capabilities

Phishing indicators

Thirteen named risk signals (typosquatting, sender-name mismatch, authentication failure, reply-to mismatch, hidden text, suspicious attachments and prompt injection among them) each shown with the evidence behind it rather than a bare score.

  • 13 risk signals
  • Evidence shown
  • Safety report

Link risk analysis

A curated lookalike map catches gmai1.example, paypa1.example and arnazon.example, alongside URL-shortener and suspicious-TLD heuristics and a check for link text that disagrees with where the link actually goes. Switch it on and it runs during sanitisation, with no external lookups.

  • Typosquat map
  • Shortener detection
  • Text vs href

Remote images blocked by default

Tracking pixels do not fire unless you let them. When you do show images they load through a short-lived signed proxy rather than straight from the sender’s server, capped at 5 MiB and restricted to real image types. Reveal them for one message, turn them on for yourself, or let an administrator disable them site-wide.

  • Blocked by default
  • Signed proxy
  • Per-message reveal

Sanitized rendering

Scripts, iframes, objects, embeds, forms and inline event handlers are stripped on the server before the message reaches your browser, links are limited to http, https, mailto, tel and cid, and what survives renders inside a sandboxed iframe under a strict content-security policy.

  • Server-side stripping
  • Sandboxed iframe
  • Strict CSP

Mailbox passphrase lock

Add a second passphrase to protect your mail. Enter it in each browser, log out to lock the mailbox again, keep background sync running, or revoke every session at once.

  • Second passphrase
  • Per-browser grants
  • Revoke all sessions

Impersonation blocking

User-switching and impersonation plugins are detected, so an administrator cannot hop into another user’s account and read their mail.

  • Switch detection
  • Mailbox isolation
  • Impersonation blocked

Audit log

Paid plans keep 365 days of recorded activity, with a pattern guard that refuses to write passwords, tokens, API keys, prompts, headers or message bodies into the log in the first place.

  • 365-day retention
  • Secrets never written
  • Admin review

Newsletter

Get useful PressedMail updates.

New releases, setup guidance, and practical ways to handle email in WordPress.

Occasional PressedMail email. Unsubscribe whenever you like.

Choose the plan that fits your WordPress sites.

Paid plans include unlimited accounts and users. Compare Premium and Ultimate features, then choose the site count you need.

Yearly plans are priced by number of sites. Lifetime is a one-time payment covering up to 100 sites.

Starter

For one site

$49/ year
1 Website
  • All current and future Premium features
  • Unlimited email accounts
  • Contacts, calendar, and email rules
  • AI tools and phishing detection
  • Layouts, themes, and workspace controls
  • Licensed updates and priority support
Most Popular

Premium

For multiple sites

$89/ year
10 Websites
  • All current and future Premium features
  • Unlimited email accounts
  • Contacts, calendar, and email rules
  • AI tools and phishing detection
  • Layouts, themes, and workspace controls
  • Licensed updates and priority support

Ultimate

For agencies

$169/ year
100 Websites
  • All current and future Premium features
  • All current and future Ultimate features
  • Unlimited email accounts
  • Contacts, calendar, and email rules
  • AI tools and phishing detection
  • Licensed updates and priority support

See how people use PressedMail for real inbox work.

...I save hours & it's easy to use...

I have a lot of email accounts and it's annoying to manage them through different providers. I installed PressedMail, added my accounts, and automated the cleanup of over 3000 emails. PressedMail has saved me hours of work.

Robert H. Alexander

Robert H. Alexander

...Helps get more clients...

As a freelancer I need to manage several clients' accounts. I installed PressedMail on WordPress on localhost and use it as my main email client. I manage everything for clients from PressedMail. And several clients use PressedMail now after I have set their WordPress instances up.

Gene Piki

Gene Piki

...Email Swiss Army Knife...

We use PressedMail as a value added service for clients and potential clients as a feature of our agency's offering helping put us ahead of competition. We love the white-labelling feature, automation, and security controls. It also replaces several of the other plugins we used to use and it's like a small CRM.

Kit M. InCurb Digital Solutions.

Kit M. InCurb Digital Solutions.

...Fast inbox organization with phishing detection...

PressedMail helps us organize our inboxes fast. We especially like the phishing detection feature.

John & Andrea

John & Andrea

...One source of truth for every client...

As a VA, I use PressedMail to keep each client's inbox separate while managing everything from one app. It gives me a single source of truth without mixing client work together.

Edhrea A.

Edhrea A.

...Teaching and client work stay organized...

I balance teaching with social media marketing clients. PressedMail helps me keep both sides of my work organized in one place.

J.A. Payo

J.A. Payo

Using PressedMail in your own work? Submit a testimonial.

FAQ

Common questions

Roadmap

See what is coming next.

Follow planned work, current progress, and recently completed features.

View Full Roadmap
  1. Shared Inboxes for Team Mailboxes

    Share a single inbox with teammates so support, order, and operations email can be monitored and handled together from WordPress.

    Planned
  2. Shared Calendars for Scheduling and Coverage

    Give teammates access to shared calendars so meetings, time off, and internal event planning can stay coordinated inside WordPress.

    Planned
  3. Calendar Sync with External Providers

    Planned two-way calendar sync with external providers like Google Calendar, Outlook, iCloud, and CalDAV so PressedMail stays in step with calendars users already have.

    Planned

Get started

Bring your working inbox into WordPress.

Compare Premium and Ultimate features, then choose a paid plan for the number of WordPress sites you manage.