# Suspicious Email & Phishing Risk Analyzer

Analyze a suspicious email or message for phishing, impersonation, malicious links, urgency tactics, and unsafe requests without clicking anything.

## Prompt

Act as a cautious phishing and scam-message reviewer. Analyze the message below without opening links, downloading attachments, contacting the sender, or assuming that displayed names and branding are authentic.

Message or email:
{{message_text}}

Optional context:
{{context}}

Review it using this structure:

1. Overall assessment: classify it as Likely legitimate, Suspicious, High risk, or Insufficient information. State confidence as Low, Medium, or High.
2. Observable warning signs: identify exact phrases, sender details, link patterns, attachment names, payment requests, login requests, urgency, secrecy, impersonation, unusual grammar, or process deviations that increase risk. Distinguish evidence from speculation.
3. Possible benign explanations: note any signs that could support legitimacy, but do not let branding or professional wording count as proof.
4. Verification plan: give safe steps using an independently found official website, saved contact, known phone number, or internal company channel. Never recommend replying to the suspicious message or using its links or phone numbers.
5. Immediate actions: explain whether to ignore, report, preserve evidence, reset credentials, contact a bank or administrator, or scan a device. Only recommend urgent account action when the message indicates credentials, payment data, or device access may already have been exposed.
6. Safe summary: provide a short explanation the user can forward to a colleague or family member.

Privacy rule: warn me if the pasted text contains passwords, verification codes, full card numbers, government IDs, private health information, or other secrets, and do not repeat those values in your response.

Do not claim certainty about the sender's identity. Do not visit or reproduce live links. This is a risk-screening aid, not proof that a message is safe or fraudulent.

## Best for

Individuals and small teams checking unexpected login alerts, invoice requests, delivery messages, job offers, bank notices, or executive impersonation attempts before taking action.

## Compatible tools

- Claude
- ChatGPT

## How to use

- Paste the message text while removing passwords, verification codes, full account numbers, and unrelated personal data.
- Add context such as how it arrived, whether you expected it, and whether the sender is known.
- Follow only the independent verification steps, not contact details or links contained in the suspicious message.
- Escalate possible credential theft, payment fraud, or device compromise to the relevant bank, employer, platform, or security professional.

## Customization tips

- Ask for a version tailored to email, SMS, marketplace chat, social media DM, or business invoice fraud.
- Include the visible sender address and link text, but redact tokens, passwords, and private identifiers.
- For workplace messages, add your normal approval process so the model can identify deviations.

## Example input

Message: 'Your Microsoft 365 account will be deleted today. Verify immediately at micros0ft-security-check.example and enter your password. Do not contact IT because this is an automated audit.' Context: I received it at work from an external address.

## Example output

Overall assessment: High risk, with high confidence. Warning signs include a lookalike domain using a zero, same-day account-deletion pressure, a request for credentials, an instruction not to contact IT, and an external sender claiming to represent an internal account process. Do not open the link or reply. Verify through your normal Microsoft 365 bookmark or contact your IT team through a known internal channel. Report the message as phishing. If you already entered a password, change it through the official account page and ask IT to revoke active sessions.
