Is It Phishing? Find Out in Seconds.

Email, SMS, QR codes, and Voice Calls — PhishyMax checks the hard facts, then explains what it found in plain language, not jargon.

Check a message now →

Free. No sign-up. Works in Arabic and English.

How it actually works

01

Fact-check

A rule-based engine checks objective facts — sender domains, links, and real SPF/DKIM/DMARC authentication when you upload the raw file.

02

Reasoning

An AI layer weighs those facts against the email's actual content and tone — catching social engineering no checklist can.

03

Plain-English verdict

You get a clear verdict and an explanation you can actually understand — in the same language as the email itself.

Check a message

🔒 Don't paste real passwords or verification codes. This is an early, independent project — great for checking suspicious messages, not for storing confidential information.

Upload a screenshot of the email instead of typing it out -- handy if you're on your phone. This uses live AI to read the image, so it needs a real connection (no demo/mock mode for this option).

Uploading the real .eml file unlocks stronger checks — real SPF/DKIM/DMARC results a pasted email can never include. Look for "Show Original" or "Download message" in your email app.

Paste the sender and message text, e.g. the "From" number/ID on its own line, then the message.

Upload a screenshot of the text message conversation. This uses live AI to read the image, so it needs a real connection (no demo/mock mode for this option).

Upload or drag a photo/screenshot containing a QR code. We'll decode it and check where it actually leads before you scan it yourself.

Upload a recording of the call (voicemail, screen recording, or an exported call recording). We'll transcribe it and check the words for phishing red flags -- this can't detect tone of voice or verify who was actually calling.