Forward the email.
Got something that feels off, an invoice you were not expecting, a login alert, a text-to-email message with a link or a phone number? Forward the whole thing to isitsafe@adaptiveips.com.
Is It Safe is a free tool from Adaptive. Forward any suspicious email to isitsafe@adaptiveips.com and we will run it through eleven separate checks and send back a plain-English verdict, usually within a few minutes. No account, no signup, no cost.
or send directly to isitsafe@adaptiveips.com
Got something that feels off, an invoice you were not expecting, a login alert, a text-to-email message with a link or a phone number? Forward the whole thing to isitsafe@adaptiveips.com.
Our pipeline picks it up automatically, usually within about 30 seconds, and runs it through eleven checks covering links, sender identity, domain history, language patterns, and attachments.
A reply lands in your inbox with a clear RED, YELLOW, or GREEN call and the specific reasons behind it, typically within a few minutes of when you hit forward.
That is the whole process. No app to install, no form to fill out, nothing to sign up for.
Every email submitted to Is It Safe goes through the same eleven checks. Here is what each one does, in plain language.
Any link in the email is checked against VirusTotal, a database that tracks known malware and phishing sites.
Links are also checked against Google's own list of sites known to host malware or phishing pages.
If the email involves a specific server or IP address, we check whether other people have already reported it for abuse.
Links are compared against phishing lists we keep cached locally, so this particular check never has to send your link out to a third party to get an answer.
We look at the technical signals email providers use to confirm a message actually came from where it claims, the SPF, DKIM, and DMARC results on the original message.
We look up how old the sender's domain and any linked domains are. A domain registered last week pretending to be your bank is a strong warning sign.
We check whether an email claiming to be from a company you know, your bank, a shipping carrier, a well-known brand, is actually coming from that company's real domain.
We check whether the sender is using a domain that was registered very recently, and whether that lines up with other warning signs like a mismatched display name or links that lead somewhere other than where the message claims.
We flag the "call this number about your account" pattern used in tech-support and subscription-renewal scams.
We read the wording of the message itself for classic pressure tactics: manufactured urgency, threats, and offers that are too good to be true.
Any attachment, Word, Excel, PowerPoint, PDF, text file, or an Outlook message forwarded as an attachment, is inspected for macros, auto-running macros, and hidden scripts embedded in PDFs. Attachments are never opened or run, only inspected.
We use three levels, and we are deliberate about what each one does and does not say.
We name the threat outright. If it is a phishing email, we say "this is a phishing email," no hedging.
Something looks off but we cannot say for certain what it is. We tell you exactly what concerned us and let you make the call with real information in hand.
Nothing we checked came back flagged. What we will not do is tell you the email is safe. A false "this is clean" is the one mistake that would make this tool worthless, so instead we tell you exactly what we checked, what we found, and we say plainly when we cannot confirm the sender's legitimacy. Green means nothing raised a flag, not a guarantee.
We built it this way on purpose. A tool that is willing to say "I don't know" is more useful than one that is always confident. That is the whole point of Is It Safe.
We do not keep a permanent copy of the email you send us. The full message stays in the mailbox we use to process it and is automatically deleted after 30 days. The details we keep to show you the verdict, like the subject line and what each check found, are encrypted at rest. Some of the checks above work by asking outside services, like VirusTotal and Google Safe Browsing about links, AbuseIPDB about IP addresses, and public domain registries about how old a domain is. That is normal for this kind of security check and is how those checks are able to work at all.
Yes. No account, no card on file, no catch.
No. Just forward the email to isitsafe@adaptiveips.com and wait for the reply.
We say so. Our YELLOW verdict exists for exactly that case, and even our GREEN verdict never claims certainty it does not have. You will always get an honest answer, not a false all-clear.
We do not keep a permanent copy of it. The full message stays in the mailbox we use to process it and is automatically deleted after 30 days; the summary details we keep to show you the verdict are encrypted at rest.
Both. We inspect attached Word, Excel, PowerPoint, PDF, and text files, along with Outlook messages forwarded as attachments, for macros and hidden scripts. Attachments are inspected, never opened or run.
Forward it to isitsafe@adaptiveips.com and you will usually have an answer in a few minutes.
isitsafe@adaptiveips.com