Anti-Phishing Email Check
Verify a scary 'action required' email in 60 seconds: headers, link destinations, official-channel check.
- What
- Verify a scary 'action required' email in 60 seconds: headers, link destinations, official-channel check.
- Cost
- Free
- Needs
- Run the 60-second triage on any unexpected security or alert email. You need: the email open in Gmail (or any client showing full headers).
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
The Anti-Phishing Email Check verifies whether a scary "action required" email is real or phishing before you click anything or share credentials. It is the five-minute triage from a real case: a "developer portal now open, complete the intake" email that turned out authentic (proper SPF, DKIM, and DMARC authentication, direct links, no redirectors) and would have been caught in sixty seconds if it had not been. The workflow has five steps. First, read the headers: in Gmail, open the message and choose "Show original", then check Authentication-Results for spf=pass, dkim=pass, and dmarc=pass, all three, with the DKIM d= domain matching the claimed sender's domain rather than a lookalike. Second, inspect every link: the visible text means nothing, the real destination is the href. Red flags are URL shorteners, redirector domains, punycode and lookalike domains, and mismatched display versus destination. Third, check the ask: credential demands, password resets, payments, or "urgent" downloads deserve high alert, and legitimate senders rarely lead with urgency plus a link. When in doubt, do not use the email's link: navigate to the official site yourself and look for the same notice in your account. Fourth, cross-check the channel: a real "portal is open" email has a public counterpart on the company's site, status page, or verified social. Fifth, decide: authentic means proceed via your own navigation, suspicious means report as phishing and delete, and if you already clicked, rotate the exposed credential immediately. The operating rules are simple: headers before links, because authentication results are harder to fake than link text. A familiar logo, your name, or "we have emailed before" proves nothing. Approval to read an email is never approval to click its links. Never forward a suspicious email's links to someone else "to check": describe it in words. And if mixed signals leave you inconclusive, treat it as suspicious and contact the company through a known-good channel.
Version:
Install
Copy the install package below, then paste it into MuseCommunity-built. Skill Harbor doesn't audit code — review the source before installing.
Run the 60-second triage on any unexpected security or alert email. You need: the email open in Gmail (or any client showing full headers). 1. Sender (0:00-0:15): open the message menu and choose "Show original". Find Authentication-Results. You need all three: spf=pass, dkim=pass with d= equal to the sender's real domain, dmarc=pass. Any fail or none is suspicious until proven otherwise. A From of [email protected] with DKIM d=random-mailer.net is a fail. 2. Links (0:15-0:35): copy each link address without clicking and read the domain. Direct and matching the claimed sender is good. URL shorteners in a "security" email, lookalike domains, and extra subdomains like secure-login.yourbank.evil.com are red flags. Display text never equals destination: always read the href. 3. The ask (0:35-0:50): credentials, password reset, payment, or "verify within 24h" means high alert. Real companies also put the notice in your account dashboard: type the URL yourself, never click through. Do not open unexpected attachments (.html, .zip, macro documents). 4. Verdict (0:50-1:00): authentic means all three auth checks pass, links are direct and match the sender, and the ask is ordinary. Proceed via your own navigation, not the email link. Suspicious means any hard fail: report phishing in Gmail and delete. Inconclusive means treat as suspicious and contact the company through a known-good channel. 5. If you already clicked: enter nothing else and close the tab. Rotate whatever it asked for (password, API key, token) from the real site, typed by hand. Check account activity for sessions you do not recognize. Rules: headers before links. Never forward suspicious links "to check": describe them in words.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.