The safest way to examine a suspicious message is to never touch it. PHISHLENS reads the text you paste and points out what is off: a sender name that does not match the address behind it, a reply that would go somewhere else, a domain one character away from a real one, link text that says one site and goes to another. It never opens the link, never loads an image, and never contacts anything.
Every check here is a rule of thumb, so read it that way. Real messages sometimes trip several of these at once, particularly ones sent through marketing platforms, and a careful fake can pass all of them. Nothing flagged means "look closer", and nothing flagged at all does not mean the message is safe. PHISHLENS never follows the link, so it cannot tell you what is actually on the far end, only what the address itself gives away. If the message claims to be from a company you deal with, the reliable answer is always to reach them through a number or address you already had, never one in the message.
Questions people ask
How do I check a suspicious email without clicking anything?
Read it as text. The sender's display name, the address behind it, the reply-to address, the authentication results and the actual destination behind each link are all in the message. Everything you need to make a decision is there, and none of it requires opening a link or loading an image.
Why does loading images in an email matter?
A remote image is fetched from the sender's server the moment the message is displayed, which confirms your address is live and reveals your IP address and the time you opened it. Most clients block them by default for exactly this reason. A message that will not display without images is telling you something.
What are the strongest signs of a phishing email?
Link text naming one site while the link itself goes to another. A domain a character or two away from a real one. A reply-to that differs from the from. Authentication that fails. And urgency about an account, a payment or a deadline. Any one of these can appear in real mail, so treat them as reasons to verify through a number you already had, never as proof either way.