Batmail

Field note: Mini study

We read every top result for "phishing email checker". Most never see the email.

Published: 6 September 2026

Last updated: 6 September 2026

On 6 September 2026 we read every first-page result Google shows in the United States for “phishing email checker”, and asked each one the same question: what do you want me to paste? Of 9 results, 3 take the email. 2 take a single address, one takes links, one is advice with no tool, and 2 would not load without JavaScript. If you are holding a suspicious email, most of what ranks for that search will never see it.

The finding

The search is for a checker that reads a phishing email. Most of the results are not that. They are address checkers built for people sending mail, link scanners built for people who have already found the link, and one good government advice page. The phrase “email checker” means two different things, and the results page is where they collide.

  • 3 of 9 read the message. PowerDMARC, Zevonix and IsThisSpam.org take the whole email, or at least its body, and say they look at the wording: urgency, the ask, the sender against the display name.
  • 2 take one address. CleanTalk and Mailmeteor are deliverability and reputation lookups: does the mailbox exist, has the address been seen spamming. Neither has anywhere to paste a message.
  • One takes links. EasyDMARC lets you paste the whole email, then by its own description pulls the links out and rates each one Good or Suspicious. A scam with no link, or with a clean link, passes.
  • One is advice. The FTC page is a plain, good explanation of how to judge a message yourself. It is not a tool and does not pretend to be.
  • 2 would not load. CheckPhish and Email Hippo answered every fetch with a bot-check page. Their own titles say link scanning and address verification, so we recorded what the titles say and nothing more.

What each page takes

Each row quotes the page’s own words: the label on the box or the instruction beside it. Our own page is at the bottom, held to the same questions. Positions are as captured on 6 September 2026.

What each page ranking for "phishing email checker" asks you to paste, checked 6 September 2026.
PageWhat it isWhat it asks forReads the emailNames the red flagsFree, no signup
CleanTalk Email Checker1st organic resultA checkerOne email address."Enter an email" (the box's placeholder). "CleanTalk email checker actually connects to the mail server and checks whether an email exists or not."NoUnknownFree, signup unknown
EasyDMARC Phishing Link Checker2nd organic resultA checkerA link, or pasted email text that it pulls the links out of."Paste URLs or email original content here." "Extracts all URLs from the pasted text. Scans these URLs to detect any issues. Tells you whether they are 'Good' or 'Suspicious'."NoNoFree, no signup
PowerDMARC Phishing Email Checker3rd organic resultA checkerThe full email source with headers, or the body only."Paste full email source (headers + body)." "We check authentication records, sender signals, suspicious links, urgency patterns, and more." "Every analysis returns a risk score from 0 to 100 and one of three verdicts."YesYesFree, no signup
CheckPhish by Bolster5th organic resultWould not loadUnknown. The page would not load without JavaScript on the day we checked.Every fetch returned a Cloudflare challenge page ("Just a moment..."). Its search result title reads "Free Phishing Link Checker & Site URL Scanning".UnknownUnknownUnknown
Zevonix Phishing Email Checker6th organic resultA checkerA whole email, with headers for best results, or just the body."Paste the suspicious email below." "For a quick check, just paste the email body text." It lists "Detecting urgent or manipulative language often used in scams" among its checks.YesYesFree, no signup
IsThisSpam.org7th organic resultA checkerAn email, a text message, a link, a phone number or a sender address, in one box."Paste a suspicious email, text, link, phone number, or sender address here..." "Receive a clear 'Low Risk', 'Needs Caution', or 'High Risk' verdict along with key warning indicators and recommended responses." "Free checks available. No signup required to start."YesYesFree to start, no signup
FTC: How To Recognize and Avoid Phishing Scams8th organic resultAdviceNothing. It is advice, not a checker.The only instruction that involves the email is a reporting step: "If you got a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org."NoNoFree, no signup
Mailmeteor Email Checker9th organic resultA checkerOne email address."Enter an email address to verify:" "Instantly verify if an email is real, active, and deliverable. No sign-up required."NoYesFree, no signup
Email Hippo10th organic resultWould not loadUnknown. The page would not load without JavaScript on the day we checked.Every fetch returned a Cloudflare challenge page. Its search result title reads "Free Email Verification Tool: Check Any Address".UnknownUnknownUnknown
Surfshark Email Scam CheckerLinked from Google's AI OverviewA product pageNothing on the page. The checker is a Chrome extension inside a paid Surfshark One subscription, run on Gmail."Launch our Chrome browser extension. Open one of your emails on Gmail.com. Prompt a scan by clicking the email scam checker box." "First, you should get a Surfshark subscription."YesUnknownPaid, account required
Batmail Phishing Email CheckerOurs, held to the same questions.A checkerThe whole message: sender, subject and body."Paste the suspicious email." "Include the sender address and subject if you have them. Never paste a password or a one-time code, and do not open attachments to copy them."YesYesFree, no signup
  • CleanTalk Email Checker. Checks the address against a spam and abuse database and whether the mailbox exists. There is nowhere to paste a message. The page's structured data prices the web check at zero; it does not say whether an account is needed.
  • EasyDMARC Phishing Link Checker. You can paste a whole email, but by the page's own description only the links in it are checked. The sender, the subject and the wording are not read.
  • PowerDMARC Phishing Email Checker. The page says the analysis runs in your browser with pattern matching and public DNS lookups, and that no data is stored. The page itself sits behind a bot check, so it was read through a text proxy.
  • CheckPhish by Bolster. Recorded as unreadable rather than guessed. By its own title it scans links and sites.
  • Zevonix Phishing Email Checker. Returns a Low, Medium or High risk level with the suspicious elements found. The page says the pasted email is not stored.
  • IsThisSpam.org. The FAQ and the sample results are loaded by the page's own script rather than present in the HTML.
  • FTC: How To Recognize and Avoid Phishing Scams. A good article. It tells you how to judge the message yourself, which is the opposite of a checker.
  • Mailmeteor Email Checker. A deliverability checker for senders: is this address valid, risky, invalid or unknown, and which check it failed. The page never mentions phishing or scams; spam appears only in the sense of a sender's mail landing there.
  • Email Hippo. Recorded as unreadable rather than guessed. By its own title it verifies addresses.
  • Surfshark Email Scam Checker. It says it analyses content and sender information, but there is no box to paste anything into on the page.
  • Batmail Phishing Email Checker. Included so we are held to the same questions. The rubric it scores against is published on the page under How it decides.

Why it matters

The phishing that reaches an inbox today mostly does not fail an address check or a link scan. It comes from a real, recently registered domain with a clean reputation, or from a compromised real account, and it often carries no link at all: a fake invoice with new bank details, a payroll change, an executive asking for gift cards, a delivery that needs a fee. Everything that gives those away lives in the wording, the ask and the context.

An address checker cannot see any of that. A link scanner sees it only when the scam bothered to include a bad link. So a person who searches for a phishing email checker, finds the first result, and pastes their sender’s address into it gets a clean answer about the wrong question, and that is worse than no answer, because it reads as an all clear.

What to look for in a checker

  • A box big enough for the whole email. If the field wants one line, it wants an address or a link, and it is not reading the message.
  • Red flags, not just a score. A number tells you what the tool thinks. The quoted wording that triggered each flag tells you whether to believe it, and lets you see the same thing in the next email without the tool.
  • A stated rubric. What does the score rest on? Ours is published on the checker’s page under How it decides, word for word the instructions the model is given, so you can argue with it.
  • A plain sentence about what happens to the text. Several pages we read say nothing. Ours: the text goes to the model that scores it and is not stored or used to train anything.
  • Honesty about what it cannot see. A checker that was given no headers cannot know whether SPF or DKIM passed (the sender checks your mail provider runs) and should say so rather than guess. That one rule is in our rubric because an early version got it wrong.

Method

The results list is the United States first page for the query as captured by Ahrefs SERP overview on 6 September 2026: nine organic results (the fourth slot was an AI Overview), plus the one product page the AI Overview linked that was not already in the list, plus our own page. Each page was fetched and read from its own text. The label on the input box or the instruction beside it was quoted verbatim, and a fixed questionnaire was answered from the page: what it is, what it takes, whether it reads the message, whether the result names red flags, whether it needs a signup, what it costs, and what the page says happens to the text.

A second, independent pass then fetched each page again and tried to refute every answer. Where the two passes disagreed, the row says unknown or carries the correction. Nothing was submitted to any tool, no account was created, and no checker was run, so this note says what each page offers and not how well it does it. Two pages could not be read by either pass and are marked as such. The date is on the page. When the results change, so will this note.

Questions

Does a phishing checker need the whole email?

For the common scams, yes. Most phishing that gets through today comes from a real address with a clean link, or with no link at all: a fake invoice, a payroll change, a boss asking for gift cards. Those live in the wording, the ask and the context, and a tool that only sees an address or a link cannot see any of it. A checker that takes the whole message can at least read what the scam says.

What is the difference between an email checker and a phishing email checker?

An email checker verifies an address: does the mailbox exist, has it been seen sending spam, will mail to it bounce. It is built for senders cleaning a list. A phishing email checker reads a message you received and judges whether it is a scam. Two of the nine first-page results for the phishing query are address checkers, which is why the query and the tool so often fail to meet.

Is it safe to paste a suspicious email into a checker?

Paste the message text, never a password, a one-time code or card details, and never open an attachment to copy it. Then read what the page says happens to the text. Of the pages we could read, three say plainly that what you paste is not stored; the rest say nothing, or answer a different question. Ours sends the text to the model that scores it and does not store it.

Which checkers actually read the email?

On the day we checked: PowerDMARC, Zevonix and IsThisSpam.org among the first-page results, plus Surfshark's paid browser extension linked from the AI Overview, and ours. CleanTalk and Mailmeteor take a single address. EasyDMARC pulls the links out of what you paste and checks only those. The FTC page is advice. CheckPhish and Email Hippo would not load without JavaScript, and their own titles say link scanning and address verification.

How was this checked, and can I repeat it?

The US results for the query were captured on 6 September 2026. Each page was fetched and the label on its input box, or the instruction beside it, was quoted verbatim, then a second independent pass tried to refute every answer against the same page. Nothing was submitted to any tool and no account was made. The date is on the page; when the results change, so will this note.

Sources

One email is a paste. A hundred a week is a job.

Batmail reads every message that lands in your Gmail overnight, flags the ones that do not add up with the reason written down, and gives you one brief in the morning. The same six-signal read the free checker uses, on the whole inbox, every night. Scout is free on one inbox.