The decision
A noul question: "this email tries to get the reader to reveal a password, pay, or open a file under false pretences". Optionally a choice over the kind: credential phishing, invoice fraud, impersonating a colleague, or none. The state is the sender, the reply-to address, the subject, the body and the real domain behind every link.
How to build it
- Serve a small model on the reader's own machine. After
pip install systemonemodels "noulxp[export,onnx]":systemone pull supersonic-labs/julia-1 --dest ./models,noulxp export julia ./models/julia-1 ./julia-noulxp, thennoulxp serve ./julia-noulxp. Mail never leaves the machine. - Write a browser extension for your webmail, or an add-in for your mail client, that reads the open message and builds the state. Use each link's real domain, not its text.
- Send the request to
POST /v1/systemoneon port 8790. A page that calls from the browser needs its origin passed to the server with--cors. - Above 0.8, show a banner: who the message claims to be from, and where its links really go. Never delete or block mail automatically.
- Test it on a folder of known phishing samples and a week of your own mail before you share it.
Make it better
Add a "report" button that saves the message and the reader's verdict. Those are labels: fine-tune on them, and the phishing aimed at your organisation in particular gets caught too.