API keys are stored locally and sent only to the PhishGuard server over HTTPS. They are never stored on the server.
When disabled, a "Scan with PhishGuard" button will appear for each email. Recommended when you want to decide for yourself when email body content (including full HTML page replicas) is analysed.
When enabled, no email data is sent to any server. Only a minimal local-only scan result is returned. Full scanning requires this to be off. Overrides all other analysis settings.
When enabled, PDF, DOCX, and image attachments are base64-encoded and sent to the server for embedded URL extraction and content analysis. Disabled by default — attachments may contain sensitive documents.
Base URL only — e.g. https://hodan.ai (no /phishguard path). Leave blank to use the default.
Optional, and only issued by your PhishGuard administrator. Adds your organization's trusted-sender allowlist and a higher scan rate limit, and lets Claude run on our server key instead of your own. You do not need this to use AI — "Claude (your own API key)" above works with no account. Sent as the x-phishguard-key header. Leave blank to run the free deterministic engine.