Safety & Review Prompts

Suspicious Email & Phishing Risk Analyzer

Analyze a suspicious email or message for phishing, impersonation, malicious links, urgency tactics, and unsafe requests without clicking anything.

FreeClaudeChatGPT
Best for

Individuals and small teams checking unexpected login alerts, invoice requests, delivery messages, job offers, bank notices, or executive impersonation attempts before taking action.

Suitable LLM groups
FrontierReasoning
Download Prompt.md
Prompt
Act as a cautious phishing and scam-message reviewer. Analyze the message below without opening links, downloading attachments, contacting the sender, or assuming that displayed names and branding are authentic.

Message or email:
{{message_text}}

Optional context:
{{context}}

Review it using this structure:

1. Overall assessment: classify it as Likely legitimate, Suspicious, High risk, or Insufficient information. State confidence as Low, Medium, or High.
2. Observable warning signs: identify exact phrases, sender details, link patterns, attachment names, payment requests, login requests, urgency, secrecy, impersonation, unusual grammar, or process deviations that increase risk. Distinguish evidence from speculation.
3. Possible benign explanations: note any signs that could support legitimacy, but do not let branding or professional wording count as proof.
4. Verification plan: give safe steps using an independently found official website, saved contact, known phone number, or internal company channel. Never recommend replying to the suspicious message or using its links or phone numbers.
5. Immediate actions: explain whether to ignore, report, preserve evidence, reset credentials, contact a bank or administrator, or scan a device. Only recommend urgent account action when the message indicates credentials, payment data, or device access may already have been exposed.
6. Safe summary: provide a short explanation the user can forward to a colleague or family member.

Privacy rule: warn me if the pasted text contains passwords, verification codes, full card numbers, government IDs, private health information, or other secrets, and do not repeat those values in your response.

Do not claim certainty about the sender's identity. Do not visit or reproduce live links. This is a risk-screening aid, not proof that a message is safe or fraudulent.

How to use

  1. Paste the message text while removing passwords, verification codes, full account numbers, and unrelated personal data.
  2. Add context such as how it arrived, whether you expected it, and whether the sender is known.
  3. Follow only the independent verification steps, not contact details or links contained in the suspicious message.
  4. Escalate possible credential theft, payment fraud, or device compromise to the relevant bank, employer, platform, or security professional.

Example input

Message: 'Your Microsoft 365 account will be deleted today. Verify immediately at micros0ft-security-check.example and enter your password. Do not contact IT because this is an automated audit.' Context: I received it at work from an external address.

Example output

Overall assessment: High risk, with high confidence. Warning signs include a lookalike domain using a zero, same-day account-deletion pressure, a request for credentials, an instruction not to contact IT, and an external sender claiming to represent an internal account process. Do not open the link or reply. Verify through your normal Microsoft 365 bookmark or contact your IT team through a known internal channel. Report the message as phishing. If you already entered a password, change it through the official account page and ask IT to revoke active sessions.

Customization tips

  • Ask for a version tailored to email, SMS, marketplace chat, social media DM, or business invoice fraud.
  • Include the visible sender address and link text, but redact tokens, passwords, and private identifiers.
  • For workplace messages, add your normal approval process so the model can identify deviations.

Tags

#phishing detection#scam review#email safety#impersonation#social engineering

FAQ

Can this prompt prove that an email is fraudulent?
No. It identifies warning signs and creates a safe verification plan, but sender identity and infrastructure must be checked independently.
Should I paste the full email headers?
You can include relevant header details if you understand them, but remove private routing information, internal identifiers, and secrets first.
Can I ask the model to open the link for me?
No. The safer workflow is to avoid the supplied link and navigate independently to the official service or contact the organization through a known channel.
What should I do if I already entered my password?
Use the official site to change the password, revoke sessions where possible, enable multi-factor authentication, and contact the relevant administrator or provider.
How is this different from a spam filter?
A spam filter automatically classifies incoming messages. This prompt provides a human-readable review of one message and a safer verification checklist.
Free

High-Risk Marketing Claims Review

Review marketing copy for guarantees, health or financial implications, fake urgency, weak evidence, hidden conditions, and claims that need specialist approval.

ClaudeChatGPT
#marketing claims#advertising review#consumer safety
Free

Prompt Injection & Tool-Use Risk Audit

Review an AI agent or tool-enabled workflow for prompt injection, untrusted content, excessive permissions, unsafe actions, and missing approval gates.

ClaudeChatGPT
#prompt injection#agent safety#tool permissions
Free

Scam Offer & Marketplace Listing Check

Assess a job offer, rental, investment pitch, freelance request, purchase listing, or online deal for scam patterns and safe verification steps.

ClaudeChatGPT
#scam detection#marketplace safety#job scam
Related skills coming soon — browse all skills.

Related Articles

Article · Safety & Review

How to Use AI to Detect Scams, Fake Emails, and Risky Messages

How to use AI as a second opinion when reviewing suspicious emails and messages, while protecting your sensitive data.

Jul 6, 20267 min read
Read How to Use AI to Detect Scams, Fake Emails, and Risky Messages