Not sure if an email is a scam? Forward it to us and find out.
Is It Safe is a free tool from Adaptive. Forward any suspicious email to isitsafe@adaptiveips.com and we will run it through eleven separate checks and send back a plain-English verdict, usually within a couple of minutes. No account, no signup, no cost.
How it works
- 1
Forward the email
Got something that feels off, an invoice you were not expecting, a login alert, a text-to-email message with a link or a phone number? Forward the whole thing to isitsafe@adaptiveips.com.
- 2
We check it
Our pipeline picks it up automatically, usually within about 30 seconds, and runs it through eleven checks covering links, sender identity, domain history, language patterns, and attachments.
- 3
You get a verdict
A reply lands in your inbox with a clear RED, YELLOW, or GREEN call and the specific reasons behind it, usually within a couple of minutes of when you hit forward.
That is the whole process. No app to install, no form to fill out, nothing to sign up for.
What we actually check
Every email submitted to Is It Safe goes through the same eleven checks. Here is what each one does, in plain language.
VirusTotal lookup
Any link in the email is checked against VirusTotal, a database that tracks known malware and phishing sites.
Google Safe Browsing
Links are also checked against Google's own list of sites known to host malware or phishing pages.
AbuseIPDB check
If the email involves a specific server or IP address, we check whether other people have already reported it for abuse.
Offline phishing-feed match
Links are compared against phishing lists we keep cached locally, so this particular check never has to send your link out to a third party to get an answer.
Sender authentication
We look at the technical signals email providers use to confirm a message actually came from where it claims, the SPF, DKIM, and DMARC results on the original message.
Domain age check
We look up how old the sender's domain and any linked domains are. A domain registered last week pretending to be your bank is a strong warning sign.
Brand impersonation check
We check whether an email claiming to be from a company you know, your bank, a shipping carrier, a well-known brand, is actually coming from that company's real domain.
New and disposable domain check
We check whether the sender's domain itself was registered very recently, then weigh that against other warning signs, like a display name that doesn't match the domain or links that lead somewhere else, the pattern that shows up when scam infrastructure gets stood up fast.
Callback scam detection
We flag the "call this number about your account" pattern used in tech-support and subscription-renewal scams.
Scam language analysis
We read the wording of the message itself for classic pressure tactics: manufactured urgency, threats, and offers that are too good to be true.
Attachment inspection
Any attachment, Word, Excel, PowerPoint, PDF, text file, or an Outlook message forwarded as an attachment, is inspected for macros, auto-running macros, and hidden scripts embedded in PDFs. Attachments are never opened or run, only inspected.
How we report what we find
We use three levels, and we are deliberate about what each one does and does not say.
We name the threat outright. If it is a phishing email, we say "this is a phishing email," no hedging.
Something looks off but we cannot say for certain what it is. We tell you exactly what concerned us and let you make the call with real information in hand.
Nothing we checked came back flagged. What we will not do is tell you the email is safe. A false "this is clean" is the one mistake that would make this tool worthless, so instead we tell you exactly what we checked, what we found, and we say plainly when we cannot confirm the sender's legitimacy. Green means nothing raised a flag, not a guarantee.
We built it this way on purpose. A tool that is willing to say "I don't know" is more useful than one that is always confident. That is the whole point of Is It Safe.
Your data
We do not keep a separate copy of the email itself. The message stays in the mailbox you forward it to until it is deleted automatically after 30 days. What we keep in our system is a derived record, sender and subject details, the verdict, and the specific findings, encrypted at rest, and the quoted parts of that record (a link, a subject line, a file name) are redacted once that same 30 days passes. Some of the checks above work by asking outside services whether something is already known to be bad: VirusTotal and Google Safe Browsing look at links, AbuseIPDB looks at IP addresses, and WHOIS looks at how old a domain is. That is normal for this kind of security check and is how those checks are able to work at all.
Frequently asked questions
Is this really free?
Yes. No account, no card on file, no catch.
Do I need to sign up for anything?
No. Just forward the email to isitsafe@adaptiveips.com and wait for the reply.
What if you can't tell whether it's a scam?
We say so. Our YELLOW verdict exists for exactly that case, and even our GREEN verdict never claims certainty it does not have. You will always get an honest answer, not a false all-clear.
Is the content of my email stored?
No, not the email itself. It stays in the mailbox you forward it to and is automatically deleted after 30 days. What we do keep, encrypted at rest, is a derived record: sender info, subject, the verdict, and the specific findings, and the quoted parts of that record are redacted on the same 30-day schedule.
Do you check attachments too, or just links?
Both. We inspect attached Word, Excel, PowerPoint, PDF, and text files, along with Outlook messages forwarded as attachments, for macros and hidden scripts. Attachments are inspected, never opened or run.
Got a suspicious email sitting in your inbox right now?
Forward it to isitsafe@adaptiveips.com and you will have an answer, usually within a couple of minutes.