TriageBox

Guide reviewed 23 September 2026. The live Chrome Web Store listing for TriageBox is 2.02. See the changelog for what shipped.

Desktop Chrome extension · Gmail, in your browser

Gmail phishing checker — no API key, Gmail’s own sender checks

TriageBox reads what Gmail already stamped on the message: SPF, DKIM and DMARC, the address a reply would really reach, and whether an attachment is a program or hides behind a second extension. One of these is a fact. Two at once is a warning. No AI. No API key. No TriageBox mailbox server.

This is not a security-company product, and it is not a banner inside gmail.com. It runs on cards in the popup. It is also not bulk unsubscribe or deleting old emails.

Free on the Chrome Web Store · no account · desktop Chrome only

TriageBox Gmail queue with unread scores, one-click archive and snooze, and an AI summary on the open thread
Scam checks on the card you are looking at, with nothing configured.

Gmail already knows

Use Show original if you can read headers. Use TriageBox if you want the sentence on the card.

Gmail on the web already filters spam and lets you Report phishing. Show original already shows Authentication-Results. Those are the source of truth. TriageBox does not replace them. It translates the same Gmail verdict, plus the reply path and the attachment’s real type, into a line on the unread card so you do not have to open the raw message for every suspicious invoice.

Job Gmail on the web TriageBox
Sender verification (SPF / DKIM / DMARC) Show original → Authentication-Results. Gmail’s servers stamp it; the sender cannot write it. Same Gmail verdict, as a sentence on the card. A DMARC fail is a caution, not an automatic accusation.
Where a reply actually goes Buried in headers. Every mail app answers Reply-To, not From. Named before you reply when that address is a different organisation — the shape of invoice fraud.
Attachment type The filename you see. Invoice.pdf.exe still looks like a PDF until you look. Judged by what it is. Nothing is downloaded. A program, or a second extension, is said in plain words.
Brand name vs sending domain You notice, or you don’t. Display name claiming a bank or large brand on an unrelated domain is a severe signal. Subjects that merely mention a brand are ignored.
When a warning fires Spam folder, or you report it. One signal is a fact. Two at once is the red banner. “Not phishing” clears that sender for good.
API key / backend None None for these checks. Optional AI (your key) is summaries, scores, and payment-fraud scoring only.
Inside gmail.com Native spam + Report phishing 0 / 10 — banners are on TriageBox cards, not a Gmail overlay
On your phone Gmail app 0 / 10 — desktop Chrome only

TriageBox is not affiliated with Google. Gmail, Google and Chrome are trademarks of Google LLC. These checks are heuristics on headers Gmail already sent. They do not guarantee detection, they do not score “96% accuracy”, and they do not replace Gmail’s spam filter. A warning you can answer is the design: a false accusation with no reply teaches you to ignore the banner, including the time it is right.

Desktop Chrome · no API key

How the no-key scam checks actually run

Add to Chrome installs this product, not the in-extension nightly log. These are the steps on a signed-in Gmail account you are authorised to use.

  1. Install and connect Gmail. Desktop Chrome or another Chromium browser. Google shows the account and permissions you are authorizing; verification warnings depend on the release and account. No TriageBox account. No API key.
  2. Open the popup queue. Newest mail stays on top. Peek a thread without clearing Unread. Each card is built locally; the scam checks run at that moment from headers Gmail already returned.
  3. Read the line, not a score. One off thing is a caution — worth reading twice, not an accusation. Two at once raises “Possible phishing” and suppresses the clickable CTA. Sign-in codes you did not request are labelled as codes, separately.
  4. Answer a false alarm. “Not phishing” trusts that sender; their mail is never flagged again. Undo in Options → Senders. Optional AI (a Gemini, Grok or OpenRouter key you add) can then score payment fraud — a change of bank details, an unfamiliar IBAN — if you want it. A routine invoice paid to the usual account is not treated as a risk.

Gmail’s verdict, not ours

SPF, DKIM and DMARC are read from Google’s Authentication-Results line. A forged pass the sender wrote is ignored.

The reply is the fraud

From can be genuine. If answering goes to a personal mailbox at another organisation, the card names that address.

The name is the signal

A program attached to an email, or Invoice.pdf.exe. Nothing is downloaded to check this.

Unsubscribe is a different page

Stopping future mail is bulk unsubscribe Gmail. Age cleanup is delete old emails. This page does not move mail.

Headers you already have, in a sentence

See the fact on the card. Warn only when two agree.

Desktop Chrome extension. No TriageBox account. Data stays in your browser. AI is optional.

Add to Chrome

Limits, stated

What this page does not claim

Quick answers

Gmail phishing checker

How do I check if a Gmail email is phishing without an API key?

Gmail already stamps every message with its own SPF, DKIM and DMARC result (Show original → Authentication-Results). TriageBox is a Chrome extension that puts that verdict on the popup card, plus whether a reply would leave the sender’s organisation, and whether an attachment is a program or hides its type behind a second extension. Nothing is sent to an AI. No API key. This is not a banner inside gmail.com — it runs on cards in the TriageBox popup and workbench.

Does TriageBox detect every phishing email?

No. It is not a security company and it publishes no detection rate. One signal is reported as a fact, because each happens to legitimate mail: forwarded messages fail DMARC, support desks answer from another domain, accountants send macro spreadsheets. Two at once is what raises a warning. You can clear a sender with Not phishing; that address is never flagged again. Gmail’s own spam filter and Report phishing remain the mailbox’s first line.

Is this the same as bulk unsubscribe or deleting old emails?

No. Unsubscribe stops future mail from a sender. Deleting old emails clears mail already in the mailbox by age or category. This page is only the no-key scam checks on the card you are looking at. Different jobs, different pages. Use bulk unsubscribe Gmail or delete old emails in Gmail for those.

Do I need an AI key for the scam checks?

No. Sender verification, reply-path and attachment typing read headers Gmail already sent. They work the minute you sign in. Optional AI (your Gemini, Grok or OpenRouter key) adds thread summaries, 0–100 scores, and payment-fraud scoring — a change of bank details or an unfamiliar IBAN. A routine invoice to the usual account is not treated as a risk. Provider limits and optional AI charges apply.

Does my mail go through a TriageBox server?

No. There is no TriageBox mailbox backend. The separate public support service counts anonymous likes; it receives no Gmail content. Processing runs in your browser; Gmail data is not sent to the publisher. Optional AI requests go from your browser to the provider whose key you added.

Desktop Chrome · Gmail you already have

No key. Gmail’s check. A warning only when two signals agree.

Free to install. No subscription. No TriageBox account.

Add TriageBox to Chrome

Trademarks and independence. TriageBox is not affiliated with, sponsored by or endorsed by Google, and it is not a Google product. Gmail, Google and Chrome are trademarks of Google LLC; xAI and Grok are trademarks of X.AI Corp. Scam checks read headers on your own mailbox in your browser. This page carries no affiliate links, no paid placement, and no invented ratings.

← TriageBox home · Bulk unsubscribe · Delete old emails · Waiting for reply · vs Checker Plus · Changelog · Privacy