MailArmour Forged to defend
Add to Chrome

Catch Phishing Before It Catches You.

MailArmour operates silently in the background, identifying the hidden clues inside modern phishing attacks to secure your inbox in real-time.

Hey! I’m Abi, your Phisher guide! I’ll show you how MailArmour spots the bad guys. Click the red buttons to explore
• The Phisher •
Evidence Lens

WHAT THE PHISHER SEES

Behind every convincing phishing email are clues. MailArmour analyzes the sender, authentication, links, content, and behavior to uncover them.

Hover over or tap the highlighted email clues to focus on corresponding evidence analyses.
IDENTITY ANALYSIS SUSPICIOUS

Sender domain does not align with the claimed organization.

URL INTELLIGENCE HIGH RISK

Destination URL redirects to a lookalike credential verification page.

CONTENT ANALYSIS CREDENTIAL HARVESTING

Message attempts to persuade the recipient to authenticate.

SOCIAL ENGINEERING URGENCY DETECTED

Message creates pressure through an artificial deadline.

BRAND IMPERSONATION DETECTED

Sender attempts to appear associated with Microsoft.

AUTHENTICATION INCONSISTENT
SPF ✓ DKIM ✓ DMARC ⚠

Authentication evidence does not provide sufficient confidence in the sender identity.

Authentication is evidence — not the verdict.
Correlating Multi-Layered Signals...
MAILARMOUR ASSESSMENT HIGH RISK
Credential Harvesting Impersonation
94/100

Multiple independent signals indicate that this message is attempting to impersonate a trusted organization and harvest credentials.

5 HIGH-RISK SIGNALS 2 WARNING SIGNALS
Illustrative Risk Score

Multi-Layered Safety Verification

🔍

Subject Header Badges

Injects visual protection status badges (Safe, Suspicious, Dangerous) right next to incoming subject headers in Gmail.

🌐

Domain Age Audit

Instantly queries WHOIS registries to flag sender domains registered within the last 30 days — a primary sign of phishing campaigns.

📎

Attachment Guards

Filters and alerts you to executable or hidden scripts (.exe, .scr, .vbs, .js) packaged inside email attachments.

📊

Local Scan Logs

Maintains a private threat statistics history dashboard completely locally in Chrome Storage for absolute data privacy.

Engine Architecture

TRADITIONAL FILTERS VS MAILARMOUR

Modern phishing doesn't always look suspicious. MailArmour connects the clues traditional filters can miss.

TRADITIONAL FILTERS

Rule-based and reputation-driven detection
Known Malicious Sender Flagged if matches active blacklist databases
Spam Reputation Filters high-volume, low-reputation mail IP ranges
Known Malicious URL Blocks links matching static security blacklists
Attachment Signature Blocks files matching known malware hash keys
WHAT HAPPENS WHEN THE ATTACK IS NEW?
Sender: trusted-service@example.com
Authentication: SPF ✓ | DKIM ✓ | DMARC ✓
URL Link: Legitimate trusted platform redirections
Reputation: Clean history, no previous reports
TRADITIONAL VERDICT LOW RISK

Looks legitimate in isolation. Static rules pass.

MAILARMOUR

Evidence-based, multi-layer phishing analysis
01
Identity Consistency Does the sender actually align with the claimed organization?
02
Authentication Deep Dive Validates SPF, DKIM, DMARC, and header consistency.
03
Domain Age & Impersonation Flags lookalikes registered within the last 30 days.
04
URL & Redirect Analysis Inspects link redirects, encoding, and display mismatch.
05
Content Harvesting Intent Detects credential harvesting, payment diversion, and urgency.
06
Behavioral Correlation Flags social engineering urgency and malicious intents.
MULTI-LAYERED CORRELATION MATRIX
Identity
+
Auth
+
Domain
+
URL
+
Content
+
Behavior
MAILARMOUR VERDICT HIGH RISK

Correlated evidence reveals intent. Mismatched signals flag danger.

KEY COMPARISON DIMENSIONS
SIGNAL DETECTION
Traditional:

Checks known indicators in isolation

MailArmour:

Correlates multiple independent signals to find hidden contradictions

UNKNOWN THREATS
Traditional:

Often relies on historical threat reputation databases

MailArmour:

Can identify zero-day behavior patterns even when domains are brand new

IDENTITY VERIFICATION
Traditional:

Compares sender address string to reputation list

MailArmour:

Audits brand names against domain registry metadata and header integrity

URL ANALYSIS
Traditional:

Queries database for blacklisted URLs

MailArmour:

Inspects URL structures, redirects, lookalike character encodings, and destinations

CONTENT AUDIT
Traditional:

Flags specific static words or simple content matches

MailArmour:

Parses context to detect social-engineering techniques and collection intents

"One signal can be misleading. Correlated evidence tells the story."

MailArmour doesn't rely on a single clue. It connects identity, authentication, URLs, content, and behavior to determine whether a message deserves trust.

Straightforward, Sincere Pricing

Free Shield
$0 / lifetime
  • 10 Lifetime Inbox Scans
  • Sender Authenticity Checks
  • Basic Attachment Guards
  • Hindi translation UI support
  • WHOIS Domain Age Registry
  • Private Dashboard Stats
  • Export threat report logs
Install Chrome Extension
Pro Shield
$2.99 / month
  • Unlimited Inbox Scanning
  • Sender Authenticity Checks
  • Advanced Attachment Guards
  • Hindi translation UI support
  • WHOIS Domain Age Registry
  • Private Dashboard Stats (50 logs)
  • Export reports (PDF, CSV, JSON)
  • Priority developer email support
Upgrade to Pro Shield

Frequently Asked Questions

Yes, entirely. We prioritize user privacy: all scans run inside your local browser. We do not store, aggregate, or sell your emails. Refer to our Privacy Policy for more details.
Most phishing domains are registered immediately before a scam campaign. MailArmour checks domain registration dates via WHOIS databases in real-time. If the sender's domain is less than 30 days old, it triggers a warning badge.
Yes. If you frequently receive legitimate emails that flag local heuristics, you can add them to your private Whitelist domain exception page to bypass alerts.
Yes, MailArmour has built-in UI localization support for Hindi, allowing users to view threat alerts and security status logs in their preferred language.