Overview
BETA: Locally analyzes opened Gmail messages for impersonation indicators after you enable protection. Not a safety verdict.
PhishCues Beta helps you inspect an opened Gmail message for impersonation cues before you decide what to do. It does not scan unopened mail and it is not a phishing, identity, legitimacy, or safety verdict. HOW IT WORKS • Gmail access is optional and requested only after you select Enable Gmail protection. • PhishCues locally analyzes only the message you choose to open. • It presents four separate fields: displayed name, From address, visible email request, and displayed links. • Links are inspected as displayed. PhishCues does not open or reputation-check them. • It provides a bounded, extractive, non-AI summary of visible message text. • Results are cautious indicators—not proof that a message is safe, legitimate, malicious, or fraudulent. • Turning protection off revokes Gmail access and removes the PhishCues interface from Gmail. GOOGLE VERIFIED AND PERSONAL TRUST A Gmail verified-sender mark may support only the displayed-name and From-address fields. The email request and links remain independent and must still be checked. Marking an exact From address Trusted is a local personal choice. It does not authenticate the sender, approve the email, override concerns in the Email or Links fields, or make the message safe. LOCAL TRUSTED AND SUSPICIOUS LISTS Trusted and Suspicious decisions apply only to the exact current From address and are stored locally in Chrome. These decisions do not alter Gmail Spam, report a message automatically, verify a sender, or upload existing local choices. OPTIONAL COMMUNITY SHARING Marking an address Suspicious always saves the decision locally first. PhishCues then opens a separate “Share privacy-safe report?” consent dialog. Closing the dialog, selecting Keep local only, turning Community sharing off, denying the optional reporting permission, or encountering a message revalidation mismatch sends nothing. To share, the user must choose one fixed reason and select Share privacy-safe report. The disclosed report contains only: • the freshly revalidated exact From address; • the bounded displayed sender name; • the Suspicious decision; • one fixed reason; • and the reporting policy version. A separate choice that defaults to No may additionally include only the exact link-free preview displayed before consent. The preview is limited to two visible top-level sentences and 220 characters. PhishCues never uploads the full email, subject, hidden headers, Reply-To, recipients, attachments, quoted history, images, HTML, links, URLs, hostnames, analysis scores, Gmail marks, or message, thread, account, tab, or document identifiers. REPORT STORAGE AND PRIVATE REVIEW Shared address and displayed-name fields are encrypted at rest. Active report rows expire within 180 days. Separately consented previews are encrypted, available only to the authenticated owner in the private moderation dashboard, expire within 30 days, and are never published on the public Cues page. Users can turn Community sharing off and request deletion of active report handles. Limited encrypted recovery history may remain temporarily after deletion to prevent replay or accidental restoration and is not normally served. COMMUNITY CUES The public Cues page contains only moderator-reviewed, thresholded domain aggregates. Shared mailbox-provider domains may be suppressed. Public Cues never expose names, complete email addresses, message content, exact report totals, or private review states. They never change the extension’s local analysis. A Community Cue represents eligible report history. It is not verification and it is not a phishing, identity, company, legitimacy, reputation, or safety verdict. OPTIONAL ANONYMOUS ADOPTION COUNTING Anonymous adoption counting is off until the user enables it. When enabled, PhishCues may send one weekly rotating random token and the applicable policy version. It sends no identity, email content, email address, domain, browsing history, or stable cross-week identifier. Aggregate adoption tokens expire within 21 days. PRIVACY AND SECURITY All executable code and deterministic analysis rules are included in the extension package. PhishCues does not download or execute remote code. PhishCues does not use Gmail OAuth or the Gmail API. It does not sell user data, display advertising, determine creditworthiness, or use user data for AI or model training. Privacy policy: https://phishcues.com/privacy Support: https://phishcues.com/support Security: https://phishcues.com/security PhishCues is for use with Gmail™. Gmail is a trademark of Google LLC. No Google approval or endorsement is claimed.
0 out of 5No ratings
Details
- Version0.8.0
- UpdatedAugust 25, 2026
- Size198KiB
- LanguagesEnglish (United States)
- DeveloperWebsite
Email
admin@phishcues.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
PhishCues has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
PhishCues handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site