Score an email for phishing signals
check_emailScores a suspicious email for phishing signals from its parsed fields. Provide any of: from_address, from_name, reply_to, return_path, subject, body_text, and links (up to 25). Returns a risk level and score with the specific flags behind them; links in the email are also checked against RelayShield's threat-intelligence corpus. A verdict of unknown means nothing conclusive was found; this tool never reports an email as safe.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| links | No | Links found in the body, up to 25. | |
| subject | No | Message subject. | |
| reply_to | No | Reply-To address, if present and different from from_address. | |
| body_text | No | Plain-text body, used for urgency/deadline/threat phrasing. | |
| from_name | No | The claimed sender's display name. | |
| return_path | No | Envelope sender, if available. Informational only. | |
| from_address | No | The claimed sender's address, e.g. alerts@phrase.com. |