Research preview · Free

See past the phish.

Verifeye is a Chrome extension that catches phishing emails in Gmail before you click. It runs entirely in your browser — no inbox uploads, no server, no ads — and tells you why a message is suspicious, not just that it is.

100% on-device No email leaves your machine Explainable verdicts
Verifeye eye mark
The problem

Spam filters miss what matters.

Modern phishing emails clear DKIM, pass DMARC, and look pixel-perfect. They land in your inbox, not your spam folder — and that's where the damage happens.

3.4B
Phishing emails / day

Phishing accounts for roughly 1 in every 4,200 emails sent — and the most dangerous ones never trigger a spam flag.

94%
Of breaches start in email

The vast majority of corporate compromises begin with a single user clicking a single link in a single message.

17s
Average decision time

That's how long a person spends judging an email. Verifeye gives you that judgment instantly, with reasons.

How it works

Install once. Protected forever.

Verifeye watches Gmail in real time. Every email you open is analyzed, and a verdict banner appears at the top — green, amber, or red — with a reasoning chain you can read in seconds.

1

Install the extension

One-click install from the Chrome Web Store. Verifeye runs locally and asks for the minimum permissions needed to scan Gmail.

2

Open Gmail as usual

No accounts to create. No setup. Verifeye watches your inbox in the background and analyzes the email you have open the moment it loads.

3

See the verdict

A clear verdict banner appears above the email — Safe, Warning, or Dangerous — with the exact reasons. One click to dismiss or trust the sender.

Detection engine

Seven layers. No black box.

Verifeye doesn't lean on a single neural network you can't inspect. It runs every email through a stack of authoritative signals and tells you exactly which ones tripped.

01

Header authentication

Best-effort SPF, DKIM, and DMARC inspection from the message headers Gmail exposes. We catch broken auth and "via" sender mismatches.

02

Sender history & ledger

Verifeye remembers every sender you've ever interacted with. New senders, sticky-flagged senders, and display-name swaps are all caught.

03

Brand impersonation

A curated registry of 130+ brands (banks, recruiters, ATS systems). Damerau-Levenshtein typo detection catches "g00gle", "micros0ft", "amaz0n" — and their lookalike domains.

04

Behavioral patterns

Unsolicited business offers, broken-language tells, urgency baiting, and template-similar mass blasts get flagged the moment they appear.

05

Link-text vs. URL mismatch

The classic phish: anchor text says "amazon.com", the URL says something else. Verifeye compares every clickable link's visible text against its real destination.

06

Attachment inspection

Suspicious extensions (.zip-in-a-pdf, .exe, .iso, double extensions) are surfaced before you click. We don't open the file — we just read what Gmail tells us.

07

Decision engine

All signals combine into a single verdict: Safe, Warning, or Dangerous — with the full reasoning chain shown to you.

In Gmail

You see the verdict where you read.

No new app to learn. The Verifeye banner appears right above the email — exactly where you already look first.

mail.google.com / inbox / "Your Chase account is on hold"
What you get

Built like a security product.

A toolbar, a popup, a real-time banner, and a full dashboard. Verifeye is what an enterprise security team would build — packaged for one person.

Bulk inbox scan

One click scans the visible inbox. Auto-scrolls through virtualized rows, shows live progress, cancellable any time.

Forensic dashboard

Every detection lands on a VirusTotal-style dashboard with charts, timelines, and the full reasoning chain per verdict.

Zero data exfiltration

No telemetry. No analytics. Your email body, headers, and attachments are read locally and discarded after analysis.

Mark-Safe button

False positive? Trust a sender once and Verifeye stops flagging that source — including its sticky-risk history.

Explainable verdicts

Every flag shows the exact reasons in plain English. No mysterious confidence score — just the signals that tripped.

Live brand registry

130+ commonly impersonated brands across banking, jobs, tech, and government. Updated with each release.

Privacy

Your email never leaves your machine.

We built Verifeye because we wanted the protection without the trade-off. Every analysis happens in your browser. Nothing is sent to a server — because there is no server.

No cloud upload

Email bodies, headers, and attachments are read by your browser and never transmitted anywhere.

No telemetry

Verifeye doesn't track you, send analytics, or phone home. We don't even know you're running it.

Open architecture

The detection logic is right there in the extension. Inspect every layer, every rule, every signal.

FAQ

Common questions.

How is Verifeye different from Gmail's built-in spam filter?

Gmail's filter focuses on bulk spam and known-bad senders. The phishing emails that hurt people are the ones that pass through it — well-crafted, single-recipient, brand-impersonating messages. Verifeye is built specifically for those. It checks brand impersonation, link-text mismatches, sender history, behavioral cues, and authentication signals together, then explains its reasoning.

Does Verifeye send my email to a server?

No. Every analysis runs locally in your browser. Verifeye has no backend service, no analytics, and no telemetry. You can verify this in your browser's network panel — Verifeye makes no outbound requests during email analysis.

What email providers does Verifeye support?

Gmail (web) is fully supported today. Outlook on the web is in active development for the v2 release. Native desktop email clients (Apple Mail, Outlook desktop) are not supported — Verifeye is a browser extension.

How accurate is it?

Verifeye uses authoritative signals rather than a single ML model trained on a dataset that ages out. Verdicts cite the exact reasons, so if it ever gets one wrong, you can see why and tell it to trust the sender. The dashboard tracks every detection so you can audit accuracy over time.

Is it free?

Yes — Verifeye is free during the research preview. We're building paid tiers with team features, OAuth-based deeper inspection, and Outlook support, but the on-device core will always be available for individuals.

Will it slow down Gmail?

No. Analysis runs in milliseconds, and the bulk inbox scanner explicitly yields control to Gmail's UI between every email — your tab stays responsive even during a 50-email scan.

Ready to see past the phish?

Install Verifeye in under 30 seconds. Your inbox stays yours.

Add Verifeye to Chrome