Skip to main content

Reading scan results

PhishNet displays a result panel for every email you open. Here's how to read it.

Threat level badgeโ€‹

The badge at the top of the panel shows the overall verdict:

BadgeMeaning
โœ… SafeNo significant threat signals. The email looks legitimate.
โš ๏ธ SuspiciousOne or more signals were detected. Read carefully before clicking links or replying.
๐Ÿšจ High riskStrong phishing or fraud indicators. PhishNet recommends not interacting with this email.

Confidence scoreโ€‹

Below the badge is a confidence score (0โ€“100) โ€” how certain PhishNet is about the verdict. This maps to the same thresholds described in How PhishNet works: 0โ€“39 is Safe, 40โ€“79 is Suspicious, 80โ€“100 is High risk. A high-risk email at 97 is more concerning than one at 82. A suspicious email at 45 might just be an unusual-but-legitimate sender.

Signal flagsโ€‹

When PhishNet detects a specific threat pattern, it shows a flag explaining what it found:

FlagWhat it means
Display-name spoofingThe sender's display name suggests a trusted person or brand, but the actual email address doesn't match
Suspicious domainThe sending domain is recently registered, typosquatted, or flagged in threat-intel feeds
Urgency manipulationThe email uses high-pressure language to push you into acting immediately
BEC patternThe email follows the structure of a business email compromise or wire-fraud attack
Risky linksOne or more links in the email point to suspicious destinations
Suspicious attachmentThe email carries an attachment type commonly used in phishing kits

Quarantined emailsโ€‹

If an email has been moved to quarantine (automatically by policy or manually by you), you'll see a Quarantined banner instead of the normal scan panel. You can restore it from there if you believe it's safe.