AIToday

Phixo launches Gmail/Outlook phishing detector with 1.4M threat signals

Hacker News2h agoSend on LINE
Phixo launches Gmail/Outlook phishing detector with 1.4M threat signals

Key takeaway

Phixo, a Chrome extension for Gmail and Outlook, detects phishing emails in under 3 seconds by analyzing 1.4M+ threat indicators across four detection layers, before users click suspicious links. The free version offers 10 daily scans; a limited-time Pro founder rate locks in $2.99/month for life. Given that 3.4B phishing emails are sent daily worldwide and the average phishing breach costs businesses $4.9M, the tool targets a gap in conventional spam filters that miss convincing lookalike domains and CEO fraud tactics.

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  • What happened

    Phixo, an AI phishing detection tool, is now available in early access as a free Chrome extension for Gmail and Outlook. It scans emails in under 3 seconds and flags phishing attempts before users click, tracking 1.4M+ threat indicators across 5 intelligence sources per scan. The free tier offers 10 scans daily; a Pro founder rate locks in $2.99/month for life (limited to first 100 users), then becomes $4.99/month.

  • Why it matters

    Modern phishing bypasses traditional spam filters by using convincing lookalike domains and well-crafted messages. The body cites 3.4B phishing emails sent daily worldwide (APWG, 2025), 91% of cyberattacks beginning with phishing (Deloitte), and $4.9M average cost of a phishing breach to a business (IBM, 2024). Phixo's real-time analysis in Gmail and Outlook aims to catch credential harvests, CEO fraud, invoice scams, and typosquats that conventional filters miss.

  • What to watch

    Phixo is live in Gmail and Outlook today; Yahoo, ProtonMail, Zoho, iCloud, and Fastmail are on the roadmap. Planned features include Inbox Sweep (in testing, Pro-only), Outlook desktop add-in (later 2026), Slack and Teams scanning (Q2 2026), and a SOC API for security teams (late 2026). Pro users receive every new feature automatically as it launches.

In Depth

Phixo is a Chrome extension for Gmail and Outlook that detects phishing emails before users click, now available in early access. The tool tracks 1.4M+ threat indicators and pulls from 5 intelligence sources per scan, returning a risk score and plain-English explanation in under 3 seconds. Installation requires one Chrome Web Store click, then sign-in via Google or Microsoft.

The body frames the phishing problem as a generational mismatch: "Modern phishing isn't a typo-ridden Nigerian prince email. It's a well-crafted message from a convincing lookalike domain — built to slip past every filter Gmail and Outlook ship with." It documents the attack chain—an email arrives from a spoofed sender (bank, Microsoft, CEO), the user clicks a link to a fake login page, enters credentials, and within eight seconds an attacker possesses the account. Recovery takes months. Against this backdrop, the body cites three data points: 3.4B phishing emails sent daily worldwide (APWG, 2025), 91% of cyberattacks beginning with phishing (Deloitte), and $4.9M average cost of a phishing breach (IBM, 2024).

Phixo's detection operates across four parallel layers: rules (instant), URL checking (fast), AI analysis (~1.5s), and domain reputation (fast), totaling under 3 seconds. The body lists the attack types it catches: CEO fraud, fake invoices, lookalike domains, typosquats, reply-to hijacking, brand spoofing, credential harvesting, wire fraud, and OAuth phishing. It shows example verdicts—a "CRITICAL" PayPal credential harvest, a "HIGH" Netflix billing scam, a "BLOCKED" malware dropper. The tool displays risk scores and explanations (e.g., the spoofed domain, the suspicious link, the manipulative phrase) so users can recognize similar tricks themselves.

Privacy is central to the pitch. Email bodies are "processed in memory and discarded the moment we return a score," never stored in the database—only a one-way cryptographic fingerprint and the verdict are kept. Links are hashed before reputation lookup. Nothing is used for training. Anonymous scan metadata (risk score, attack type, timing) is retained for scan history and model improvement.

Pricing offers a free tier (10 scans daily, all four detection layers, Gmail & Outlook, full explanations) and a Pro founder rate locked at $2.99/month for life, limited to the first 100 users; after that, Pro becomes $4.99/month or $39/year. Pro includes unlimited scans (capped at a fair-use limit of 300 per day to prevent abuse), full scan history, custom trust and block rules, priority AI lane, and all future Pro features included free.

The roadmap spans 2026. Inbox Sweep, currently in testing and Pro-only, will retroactively scan the last 30 days of mail in one click. A native Outlook desktop add-in, shipping later in 2026, targets users on Outlook desktop where browser extensions don't reach. Slack and Teams scanning launches Q2 2026 to cover inbound links in workspace channels. A SOC API, planned for late 2026, will allow POST requests from SIEMs and SOAR platforms for four-layer analysis. Currently a single-user product, a team plan will ship when the API does. Phixo is published on the Chrome Web Store by Phixo Labs, passed Google's extension review, and requests only minimum permissions needed to scan open emails. Its codebase ships inside the reviewed package with no remote code loaded; analysis is processed in real time on Phixo's servers and by its AI provider under a no-retention agreement, then discarded immediately.

Context & Analysis

Phixo enters a market where traditional spam filters have failed to keep pace with modern phishing tactics. The body documents the scale of the problem: 3.4B phishing emails are sent globally per day (APWG, 2025), and Deloitte reports 91% of cyberattacks begin with phishing. The financial stakes are concrete—IBM's 2024 data puts the average phishing breach cost at $4.9M per business. Traditional filters rely on known-bad sender lists and simple heuristics; Phixo's stated approach is to layer four independent checks (rules, URL scanning, AI, and domain reputation) in parallel and weight the combined signal, aiming to catch new attack types rather than only repeat patterns.

The product design emphasizes speed (under 3 seconds) and transparency. The body shows sample phishing emails (PayPal credential harvesting, Microsoft account spoofing) and highlights attack types it targets: CEO fraud, fake invoices, lookalike domains (typosquats), and reply-to hijacking. Crucially, the body states that email bodies are "processed in memory and discarded the moment we return a score" and "never written to our database," positioning privacy as a structural feature rather than a policy promise. The pricing model—$2.99/month locked-in for life for the first 100 founders—is a founder-acquisition tactic common in early-stage security tools, intended to build early adoption before raising prices.

FAQ

How much does Phixo cost and what's included?
Phixo is free with 10 scans per day, including all four detection layers and full risk explanations. The Pro founder rate is $2.99/month (locked in for life) and is limited to the first 100 users; after that, Pro becomes $4.99/month or $39/year. Pro includes unlimited scans (subject to a fair-use limit of 300 scans/day), full scan history, custom rules, priority AI lane, and all future Pro features included free.
Where does Phixo work, and what's planned next?
Phixo is fully live in Gmail and Outlook today. Yahoo, ProtonMail, Zoho, iCloud, and Fastmail are on the roadmap, shipping in order of user demand. Planned features include Inbox Sweep (retroactively scanning the last 30 days, in testing for Pro), Outlook desktop add-in (later 2026), Slack and Teams scanning (Q2 2026), and a SOC API for security teams (late 2026).
Does Phixo store or use my email data?
Email bodies are processed entirely in memory and discarded immediately after a risk score is returned—never stored, logged, or used for training. URLs are hashed (one-way) before reputation lookup. Only anonymous scan metadata (risk score, attack type, timing) is retained to show scan history and improve detection.

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Discussion

No discussion yet for this article

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime