ThouShaltNotClick — Phishing Protection & Training
Overview
Catches phishing in Gmail and Outlook. Real-time link analysis, breach alerts, and in-context security training.
1.9.149 • Trust-score engine v2 now stays in sync with ThouShaltNotClick's servers automatically - scoring updates roll out centrally, without needing an extension update. • Reliability and performance improvements. 1.9.148 • Fixed: the extension could appear signed in while every check silently failed, if your school requires two-factor authentication and you hadn't finished setting it up • Fixed: routine subscription and invoice emails were sometimes flagged as possible phishing • Fixed: a reply in a conversation you're part of is no longer treated as a cold approach from a stranger • Fixed: badges now appear as soon as you sign in, without needing to reload the tab • Improved: warnings now explain which specific signal triggered them, and how confident we are • Improved: links rewritten by a corporate email gateway are unwrapped before analysis v1.9.139 • Fewer false alarms, one real hole closed. • Banks, parishes and dioceses are no longer scored as impersonators. • Better detection of payment-fraud (BEC) style messages, and more accurate sender identification. • Closed a genuine sender-spoofing gap found in a security audit. v1.9.135 • Fewer false alarms on shared documents. A genuine "shared a document with you" email from Google Docs/Drive (and Dropbox, DocuSign, etc.) is no longer mistaken for impersonation. Google's own "(via Google Docs)" sharing notation was being read as a spoofed sender — that's fixed, while a real impersonation ("Google Security" from a fake address) is still caught. • Clearer guidance on caution emails. When an email says "tread carefully," the recommended action now stresses the real tell: verify anything you didn't expect through a separate channel — and if you call, use a phone number you've already confirmed, never one from the email itself. • Cleaner banner on our own emails. On official ThouShaltNotClick emails the banner no longer repeats our name (it used to read "ThouShaltNotClick: ThouShaltNotClick 99/100"); it now shows the normal rating, e.g. "Most Likely Safe." v1.9.132 • Stronger link privacy. When you click a link and ThouShaltNotClick checks it, the extension now strips the link's query string and one-time token on your device before anything is sent for the safety check. Password-reset and "magic" sign-in links carry a live credential in that part of the address — it now never leaves your browser; only the site, domain, and path are checked. Under the hood: your email's contents are analyzed entirely on your device and never sent anywhere. When a sender isn't already in your local threat cache, only the sender's address and subject line are checked against known scam campaigns — metadata, never the message body. v.1.9.127 - Better support for the new Outlook • The trust badge now reliably appears in the new Outlook (outlook.cloud.microsoft) — it previously could fail to show. • The extension now correctly reads the message sender in the new Outlook, so the green "Verified Safe" and familiar-sender cues work again — and it won't mistake a recipient for the sender. • Recognizes simulation-training emails no matter which domain they're sent from. • Reliability and stability improvements under the hood. v.1.9.118 • One-click AI image scanning Open the extension and hit "Scan this page for AI images" — no more right-clicking. TSNC checks the images on the page, outlines the likely AI-generated ones in orange, and shows you a confidence score for each one right in the popup. v1.9.117 • New — "Is this image AI-generated?" Right-click any web page → "Check this page for AI-generated images" (or right-click a single image) and TSNC flags likely AI-generated images with an orange border and a confidence %. Handy for spotting fake profile photos, fabricated screenshots, and AI-generated scam imagery. Nothing on the page changes — it's just an overlay you can clear anytime. • Sharper detection Trust scores no longer show "null" on group/BCC emails. Better detection of gift-card and payment-scam wording. • Polish Smoother trust banners and quicker, more reliable page scanning. v1.9.113 • Calmer, clearer warnings. Trust levels now guide rather than judge — "Tread Carefully" replaces "Suspicious," and the safe end is clearer with "Most Likely Safe" and "Should be Safe." Less alarm fatigue on everyday mail means the genuinely dangerous ones stand out. • Smarter scoring, fewer false alarms. Security notices that mention sensitive information — like "we will never ask for your Social Security number" — are no longer scored as though they asked for it. • Lighter on your browser. The extension now checks in only while Gmail or Outlook is actually open, cutting most of its background activity. • No more double banners. When the extension shows its own live trust banner in Gmail, it now reliably hides the one added at delivery. • Community Alert counts again. Flagging one of our simulated phishing emails now correctly credits your catch. • Sharper icons. Fixed a stretched shield logo and cleaned up the toolbar icon at small sizes. • Naming. "Mobile Coverage" is now "Complete Coverage." • Plus reliability and security hardening under the hood. v 1.9.104 Mobile Coverage — no more double banners. If your school adds ThouShaltNotClick's trust-score banner to incoming email, the extension now hides that in-email banner on your computer and shows its own always-current badge instead — so you see it once, not twice. Licensing clarity. The extension now reflects your organization's ThouShaltNotClick license across email checks, link scans, and AI analysis. If your administrator hasn't assigned you a seat yet, you'll get a clear, friendly prompt to reach out to them — instead of the extension quietly doing nothing. Security hardening. Tightened verification on in-page "report" and "alert" actions so they only run from trusted webmail pages. v1.9.99 - Content Filtering (optional, admin-controlled). Schools can block website categories for students (hard block) and staff (off / warn-and-proceed / hard block), with allow/deny overrides admins can add right from the browser. Enforcement is local — no browsing history is collected; only blocked-site events are recorded for the school's own administrators, and only when a school enables the feature and accepts the Content Filter Addendum. Off by default — existing users see no change. v1.9.90 - QR Code scanning, protection against shared-file and invite spam, more accurate trust scores, lighter on the browser, bugfixes. *New: Protection against "shared-file" and invite spam. Scammers increasingly abuse legitimate Google sharing — they share a Google Drive/Docs file or a Google Forms invite that hides a fake invoice, a "rate request," or a phishing link. These slip past normal spam filters because the email genuinely comes from Google. The extension now flags them: it spots the share/invite, checks whether the person who shared it is an outside, unverified sender, and scans the title for known scam patterns — then warns you before you open it. Files shared by your own colleagues or your organization's approved contacts are never flagged. *New: QR Code Scanner (anti-"quishing"). QR codes can hide malicious links, and you can't tell where one points just by looking. The extension now scans the current page for QR codes and reveals each code's real destination before you ever trust it: *Scan the visible page from the extension popup, or right-click a single QR code to check just that one. *Each code gets a numbered "Copy link" pin placed right on it, with the matching link listed in the popup — so on a page with several codes, you always know which is which. *Every detected link is automatically checked against malicious-site databases. *Works on real-world pages — codes delivered as images of any format, including cross-origin images and codes inside embedded frames. *Everything is decoded locally on your device. No images are uploaded. *More accurate trust scores. The on-page trust badge now uses the exact same scoring engine as our servers, so scores are consistent everywhere — and it now catches additional suspicious signals in message content it previously missed. Lighter on your browser. Community threat updates now refresh only when something actually changes instead of polling on a fixed timer — the same real-time protection with less background data and battery use. Forwarded-email warning. When you report a forwarded message as a community threat, the extension now warns you first, so a forwarded sender doesn't get flagged by mistake. Cleaner popup. The popup's tools are now grouped into a single, consistent "Tools" section (Quick Link Scanner and QR Code Scanner), so everything looks uniform — with room for more tools to come. v1.9.78 — faster protection, broader Outlook support, more privacy • Protection works the moment you install. Phishing badges now appear on your emails right away instead of waiting a few minutes after setup. • Now works on Outlook's new web address. Added support for outlook.cloud.microsoft — Microsoft's new unified Outlook-on-the-web domain — so badges, link analysis, and the Kindness Meter all work there too. • "Community Alert" now counts. Flagging a training/simulation email with Community Alert credits you the same as "Report Suspicious." • Minor fixes and polish. ThouShaltNotClick adds a quiet layer of protection inside Gmail and Outlook — analyzing every link, every sender, and every header, then warning users in plain language before a click can do harm. Phishing protection A clear trust badge appears in the email header, with green for safe, yellow for caution, and red for danger. Each warning explains why a message looks suspicious — never just a score — so users learn what to watch for over time. Hover any link to see where it actually leads, even when the visible text says otherwise. A one-click report sends suspicious emails to your administrator for verification, helping protect everyone in your organization. Personal email addresses can be checked against known data breaches so you know when to rotate a compromised password — using a privacy-preserving check that never sends the password itself. Site safety The extension icon shifts color based on the current page — giving you an at-a-glance read on whether the site you're on has been flagged. When new threats are reported and verified by an administrator at one organization, protection updates for everyone using the extension. Built for organizations who care about their people ThouShaltNotClick was built specifically for Catholic schools and faith-based organizations, is accessible to all, and works equally well for any team that needs phishing protection without enterprise complexity or pricing. Administrators can enroll an entire staff in minutes, and managed Chromebook deployment is supported. Privacy Email content is analyzed locally; no message body is sent to our servers unless you explicitly request a deeper analysis. We do not collect browsing history. Get started Sign in with your existing ThouShaltNotClick account, or create one free at https://www.thoushaltnotclick.com. Created by a Catholic — accessible to all.
0 out of 5No ratings
Details
- Version1.9.149
- UpdatedSeptember 24, 2026
- Offered byeducationtechopros
- Size562KiB
- LanguagesEnglish
- DeveloperEducation Technology Professionals, LLC
214 Harmersville - Pecks Corner Road Salem, NJ 08079 USEmail
info@educationtechpros.comPhone
+1 215-201-5964 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S100368106
Privacy
ThouShaltNotClick — Phishing Protection & Training has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
ThouShaltNotClick — Phishing Protection & Training handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site