AI-assisted email safety

A second opinion before you click.

Forward, paste or upload a suspicious email. Percival examines the sender, wording, links and attachments, then explains what you should do next.

Private by design · Plain-English results · No unnecessary storage

Product demonstration
From
HM Revenue & Customs Support
High risk
Subject
Your tax refund is waiting

You are eligible for a tax refund of £428.17. Complete the verification process within 24 hours to avoid cancellation.

Percival found
  • • The sender domain does not match HMRC
  • • The link redirects through an unrelated website
  • • The message uses artificial urgency
  • • The email requests sensitive financial information
Recommended action

Do not follow the link. Delete the email and visit GOV.UK directly if you need to check your tax account.

Technical details
sender_domain=hmrc-refund-check.example.net
visible_link=gov.uk-refund-check.example.org/login
risk_evidence=urgency,mismatch,credential-request
Sender analysisLink inspectionAttachment checksImpersonation detectionUrgency and pressure signalsPlain-English guidance
Sender analysis, Link inspection, Attachment checks, Impersonation detection, Urgency and pressure signals, Plain-English guidance
The problem

The most convincing scams do not look obviously suspicious.

Modern phishing and impersonation emails often use familiar brands, believable language and urgent requests. Percival helps you pause, inspect the evidence and decide what to do next.

A familiar logo is not proof of identity.
A convincing message can still contain a dangerous link.
Urgency is often used to stop you checking.
How it works

From uncertain message to clear next step.

Percival combines rule-based checks, observed evidence and plain-language guidance so the result is easier to understand.

01

Observe

Percival examines the sender, message content, links, attachments and visible email details.

02

Compare

It looks for inconsistencies, impersonation signals, known threat indicators and unusual requests.

03

Advise

You receive a clear risk level, supporting evidence and a practical recommendation.

See the full process
Interactive example

A large email example with the evidence beside it.

The product experience is designed to show where the problem is, not just to label the outcome.

From: Microsoft Account Team <accounts@alerts-example.net>
Subject: Sign-in required to prevent account closure

We noticed unusual activity on your account. To avoid account closure, please confirm your sign-in immediately.

Review your sign-in details

If you do not verify within the next hour, your mailbox access may be limited.

Attachment: account-review.html

Display-name impersonation

The visible sender name says Microsoft, but the address uses an unrelated domain.

Link destination mismatch

The button text appears legitimate, but the underlying link points somewhere else.

Artificial urgency

The message demands immediate action to prevent account closure.

Unexpected sign-in request

The message asks the user to authenticate without prior context.

Unusual attachment

The attachment type is commonly used to deliver malicious content.

A result you can understand.

Percival keeps the recommendation prominent, then shows the evidence and the uncertainty around it.

Likely safe

Likely Safe

No significant warning signs were identified from the information available.

Recommended action

Continue with normal caution.

A reassuring result does not guarantee that the message is genuine or harmless.

Needs caution

Needs Caution

Percival found inconsistencies that should be checked independently.

Recommended action

Contact the organisation using a trusted phone number or website.

Some legitimate emails can still look unusual, especially when account details change.

High risk

High Risk

The email contains strong indicators of phishing, impersonation or malicious activity.

Recommended action

Do not reply, follow links, make payments or open attachments.

This result is based on the information available and should be treated as urgent caution, not proof of intent.

What Percival helps you recognise.

The threat library gives plain-English examples of common email scams and what each one is trying to achieve.

Privacy by design

Your email is evidence, not our product.

Percival processes the information required to assess a message and provide a result. It should not retain email content for longer than necessary to operate the service, investigate faults or meet clearly stated legal obligations.

Purpose limitation

Email content is processed only for defined security and service purposes.

Data minimisation

Only the information needed to assess the message should be collected.

Clear retention

Users should be told how long submitted content and results are retained.

Human judgement

Percival supports decisions but does not replace independent verification.

Read our privacy approach

A useful second opinion, not an absolute guarantee.

Percival is designed to support responsible decisions, not replace them.

Percival may not identify every malicious email.
A clean result does not prove that a message is safe.
External reputation services may have incomplete information.
New threats may not yet be widely recognised.
Sensitive or regulated information should not be submitted unless the service is approved for that purpose.
When money, passwords or urgent requests are involved, verify the request independently.
Ready when you are

Unsure about an email? Ask Percival before acting.

It takes only a few moments to get a plain-English assessment.