PhishGuard
IT admin? Deployment guide →

PhishGuard

Warns you when an email changes where your money goes.

It checks every email you open in Gmail and Outlook for vendor impersonation, look-alike domains and phishing — quietly, before you click.

Download for Chrome

Gmail and Outlook on the web · no account, nothing to configure

Then load it into Chrome — four steps, two minutes
  1. 1

    Download the extension

    Save the ZIP anywhere and unzip it. You'll get a folder called "extension".

  2. 2

    Open Chrome's extensions page

    Type chrome://extensions in the address bar, or menu (⋮) → Extensions → Manage Extensions.

  3. 3

    Turn on Developer mode

    The toggle is in the top-right corner of that page.

  4. 4

    Load unpacked

    Click "Load unpacked" and choose the unzipped "extension" folder. PhishGuard appears in your toolbar — that's it.

What happens next

  • It works silently. Every email you open is checked. When it's clean you see nothing — a small green tab at the edge of the page is the only sign it ran.

  • It speaks up when something's off. A panel opens with one plain sentence on what to do, and the reasons underneath. Amber means verify before acting; red means don't.

  • Tell it when it's wrong. Every verdict has a button for that. A wrong flag stops repeating for that sender; a missed phish teaches the engine what to look for.

What it catches

Changed payment details

"Our banking details have changed — send payment to the new account." The most expensive email a business receives, flagged whoever it comes from.

A familiar name, a new address

A vendor who has always written from their company suddenly writes from Gmail. Your own mailbox history catches it — no server needs to know who your contacts are.

Replies going somewhere else

The sender looks right, but replies are quietly routed to an attacker's address. Checked on Outlook, where the mail headers are readable.

Look-alike domains

A supplier's domain with one character changed, a big-name brand signed from a personal mailbox, a domain registered last week — checked before you can click.

Using the Outlook app?

If your organization deployed PhishGuard, it's already in your Outlook — open any email and look for the PhishGuard button. Pin the pane (📌) so it follows you through the inbox. On a personal outlook.com account, add it yourself:

  1. 1.Outlook on the web → open an email → ⋯ → Get Add-ins
  2. 2.My add-ins → Add a custom add-in → Add from URL → paste the link above
  3. 3.Open a message → ⋯ → PhishGuard

Personal details — addresses, phone and card numbers, SIN/SSN, postal codes — are masked in your browser before anything is sent. Your email is never stored. AI is off unless you or your admin turn it on. Read exactly what leaves your computer →

IT deployment guide·Privacy·Assistive, not a guarantee — always verify unexpected requests through a channel you trust.