Anti-phishing for your whole company. And your kitchen table.

Modern phishing is AI-written, pixel-perfect, and lands from senders you recognize. PhishFry blocks the bad clicks at the browser, catches BEC and wire-fraud pretexts before they land, trains your team with a 1,160-email inbox simulator, and hands your auditor a print-ready SOC 2 report. One product, two audiences.

โœ“ Plans from $5/month ยท โœ“ Scoring runs locally ยท Chrome Firefox Safari Gmail
๐ŸŸ

One product. Two ways to use it.

The extension protects every user's browser. The platform gives admins the training and audit story they need. Pick the parts you want.

For teams

Run it across the whole company.

Roll out the extension to every laptop via MDM or your admin console. Enroll members into an org account, set a training cadence, turn on simulated phishing, and watch the admin dashboard fill in.

  • Org accounts with member roles, invites, and org-level settings
  • PhishTest โ€” a 1,160-email training simulator members retake in fresh batches
  • Simulated phish injected into real Gmail / Outlook inboxes on your cadence
  • Report-to-PhishFry button in the Gmail / Outlook toolbar
  • Per-family scam-accuracy heatmap and per-member training status
  • Print-ready SOC 2 / HIPAA / PCI-DSS training-evidence PDF
  • Enterprise MDM / Group Policy / Chrome Admin Console support
Set up your team
For individuals

Same extension. Same protection.

If you just want a browser that flags the bad links and warns you before you enter a password into a lookalike, that's what the free-agent side of PhishFry is for. Optional family plan covers up to four people.

  • Chrome, Firefox, and Safari extensions (macOS + iOS)
  • Gmail Workspace add-on scores links inside every email you open
  • Link-hover tooltip: green = safe, red = stop
  • BEC / gift-card / wire-fraud / crypto-drainer detector โ€” no URL needed
  • Clipboard, QR-code, and open-redirect protection
  • Family plan: 4 seats, one bill
Get it for yourself

Everything phishing throws at you, handled.

Six pillars, one product, two surfaces (browser + admin dashboard).

๐Ÿ›‘

Block

Extension scores every link before it's clicked. Lookalike domains, suspicious TLDs, freshly-registered traps, brand impersonation โ€” scored 0-100 locally, no URLs leaving your machine.

๐ŸŽฏ

Detect

A 50+ scam taxonomy (BEC, credential harvest, financial fraud, malware delivery, social/emotional) catches the pretext side โ€” gift-card asks, wire-fraud, sextortion โ€” even when no URL is malicious.

๐ŸŽ“

Train

PhishTest is a Gmail-clone inbox with 1,160 curated emails (500+ phish across ~250 brands). Members retake in fresh batches โ€” no repeats until they've cycled through every batch.

๐ŸŽฃ

Simulate

Turn on sim campaigns and the extension injects one fake phish into each member's Gmail or Outlook inbox on your cadence. Click โ†’ "gotcha, this was training." No SMTP, no deliverability risk.

๐Ÿ“ฎ

Report

One-click "Report to PhishFry" button in the Gmail / Outlook toolbar. Every submission lands in the org dashboard with sender + subject + top-domain rollup. Turns every user into a sensor.

๐Ÿ“„

Prove

Print-ready training-evidence report an auditor accepts. Covers SOC 2 CC1.4 / CC5, HIPAA 164.308(a)(5), PCI-DSS 12.6, NIST 800-53 AT-2, ISO 27001 A.7.2.2 in one document.

Phishing got really good.

It's not Nigerian-prince emails anymore. Modern phishing is AI-written, pixel-perfect, and shows up in your inbox from sender addresses you've seen a hundred times.

These are the patterns PhishFry catches and trains against.

g00gle-l0gin.tk 22 / 100

Lookalike domains

Zeros for o's, ones for l's, swapped letters. Brand-impersonation check tanks the score before the hover tooltip finishes drawing.

"Are you at your desk?" ยท sarah.ceo@gmail.com BEC

CEO wire / gift-card BEC

Modern BEC uses your real CEO's name, a freemail sender, and a "sent from my iPhone" signature. Scam detector flags exec-name + freemail-domain + urgency in one pass.

"Package undeliverable โ€” $1.99 fee" USPS scam

Fake delivery / TOAD

Package-redelivery scams are the #1 SMS/email fraud in the US. Callback (TOAD) scams that ask you to phone a number to "dispute a charge" are second. Both are in the taxonomy.

"Enter your 12-word recovery phrase" Wallet drainer

Crypto wallet drainer

Fake Coinbase / MetaMask / Ledger emails asking for seed phrases. Critical single-signal trigger โ€” one hit and the warning banner fires.

"Please update our new banking details" Vendor bank change

Vendor invoice fraud

Real (or compromised) vendor sends an invoice asking payment to a new bank account. Highest-loss BEC category. Detector flags "new bank account" + digit-run + urgency.

"So-and-so shared Q4 Plans" Fake Doc share

Fake Google Doc share

Fake "shared with you" notification from a wrong sender. Extension unwraps Gmail + Outlook SafeLinks wrappers so we score the real destination.

What each employee sees.

Install the extension. That's it. It just works in the background.

Hover a link ยท get the score

Every <a> tag on every page gets a score. Green (80+) means safe, amber (50โ€“79) means caution, red (below 50) means don't click. Scores of 90+ hide their tooltip so clean pages don't get noisy.

  • Configurable warn / block thresholds
  • Runs locally โ€” no URL leaves the machine
  • Whitelist and blacklist for personal overrides

Open an email ยท see the tells

Gmail and Outlook web get a warning banner when the message matches a scam-taxonomy pattern. The banner names the family (CEO wire, credential harvest, package undeliverable) and gives the safe action verbatim.

  • Body-URL scanner catches sneaky links inside compromised-friend messages
  • Email-peek shows a color dot next to inbox rows before you open
  • Report-to-PhishFry button in the message toolbar for one-click reporting

What admins see on /org/admin.

One dashboard. Every visibility gap a security lead usually has to piece together from three tools.

Training status
12 current ยท 3 stale ยท 1 overdue
Scam-family accuracy (this month)
BEC 67% ยท Credential-harvest 92% ยท Financial-fraud 81%
Sim phish ยท last 30d
15 delivered ยท 2 clicked ยท 9 reported
Reported phish (this week)
alice@acme.com โ€” service@paypa1-alerts.com โ€” "Your account has been limited" โ€” sim โœ“
bob@acme.com โ€” orders@amaz0n-billing.com โ€” "iPhone order confirmation โ€” $1,299"
carol@acme.com โ€” refunds@irs-refund.us โ€” "Tax refund pending"
Top domains (30d): paypa1-alerts.com ยท docusign-secure.co ยท usps-track-notice.info

PhishTest โ€” the training simulator.

1,160 hand-curated emails across ~250 brands, grouped into 58 batches of 20. Members retake the test in fresh batches โ€” no repeats until they've cycled through the whole bank.

1,160
Curated emails
500+
Phish variants
~250
Brands impersonated
58
Retake-safe batches
5
Scam families

Every phish carries a taxonomy tag (BEC, credential harvest, financial fraud, malware delivery, social/emotional). The admin heatmap shows which categories your team gets wrong, so training focuses on the actual weak spots.

Simulated phish, without SMTP.

KnowBe4-style training-in-real-inboxes, with none of the deliverability wars. The Chrome extension injects one fake phish per member into their Gmail or Outlook inbox on your cadence. Click โ†’ "gotcha, this was training" page.

1

Admin turns it on

Pick a cadence (weekly / bi-weekly / monthly). Optionally target specific scam families (BEC only for finance, credential-harvest only for devs).

2

Extension injects

Next time each member opens Gmail or Outlook, the extension adds one synthetic row to the top of the inbox. Looks native. No email actually sent.

3

Outcome measured

Click โ†’ landing page reveals it was training. Hit Report โ†’ counts as a save. Ignore for 48h โ†’ recorded. Admin dashboard shows per-member results.

Why the extension does the injection: no SMTP means no risk of a legit training email landing in spam, no sender-reputation damage, no OAuth scopes to audit. Trade-off: desktop Chrome-in-Gmail/Outlook only for v1.

Auditor evidence in one PDF.

Every framework wants the same thing: proof you train your workforce regularly and measurably. PhishFry generates that proof on demand.

SOC 2

CC1.4, CC5 โ€” documented, ongoing security-awareness training for all workforce members.

HIPAA

164.308(a)(5) โ€” per-employee completion records + ongoing training program evidence.

PCI-DSS

12.6 โ€” annual (or more frequent) security awareness training with measured effectiveness.

NIST 800-53

AT-2 โ€” role-based training records with measurable outcomes per member.

ISO 27001

A.7.2.2 โ€” formal awareness program with employee-level records.

One click โ†’

Admin hits "Open report" on /org/admin. Browser prints the report to PDF. Auditor gets what they asked for. Sales cycle shrinks.

What goes into the URL score

Six-plus signals, combined into a 0โ€“100 number you can read at a glance.

๐Ÿท๏ธ

TLD reputation

.gov, .edu, and .mil score high. Frequently abused TLDs like .tk, .xyz, and .gq score low.

๐Ÿ“ˆ

Popularity union

Tranco top-500K, Umbrella top-1M, and Cloudflare Radar combined. Domains the world already trusts get a boost.

๐Ÿ•ต๏ธ

Heuristic red flags

Phishy keywords (login, verify, secure), embedded TLDs, long numeric runs, urgency words. Path signals beyond the hostname.

๐Ÿ“…

Domain + certificate age

RDAP lookup for registration date + CT-log-derived cert-age bloom. Brand-new domains score down; long-lived indie sites get a modest boost.

๐ŸŒ

Threat-feed union

PhishTank + OpenPhish + Netcraft + URLhaus, refreshed weekly. Bundled snapshot ships with the extension so day-zero users are covered.

โœ…

PhishFry Verified

Site owners can verify ownership via meta tag or DNS TXT and earn a score boost.

Try it on any URL

Type a URL โ€” real or phishy โ€” and see how it scores. Runs entirely in your browser.

๐Ÿ”
โ€”
Enter a URL above

The demo uses a simplified subset of the scoring engine. The installed extension factors in the popularity union, RDAP domain age, CT-log cert age, threat-feed union, and the scam-detector taxonomy on top of what you see here.

Run a legit site? Get verified.

Prove your domain is yours with a meta tag or DNS TXT record. Verified sites get a green checkmark in tooltips + a +15 score boost. Free.

Meta tag
<meta name="phishfry-verified" content="YOUR_TOKEN">
DNS TXT
_phishfry.example.com TXT "phishfry-verify=YOUR_TOKEN"
Get a verification token
โœ“
Verified
example.com

Pricing

Extension is the same on every plan. Higher tiers add the platform: training, sims, admin dashboard, compliance report.

Individual

Extension for one person.

$5 /month

Paid annually ยท $60 / year

  • Chrome / Firefox / Safari extensions
  • Gmail Workspace add-on
  • Scam-detector (BEC, wire fraud, wallet drainer, TOAD)
  • Personal whitelist & blacklist
  • Configurable thresholds
Get Individual

Family

Extension for the household.

$12 /month

Paid annually ยท up to 4 users

  • Everything in Individual
  • 4 users included ยท $3/user for more
  • Each member's settings stay private
  • One bill
Get Family

Enterprise

Managed rollout at scale.

Contact

Custom pricing ยท 100+ users

  • Everything in Business
  • Group Policy / MDM / Chrome Admin Console deployment
  • Self-hosted SIEM aggregator for crowd-intel telemetry
  • Volume pricing, procurement + invoicing
  • Priority support + onboarding
Contact Sales

Score URLs from your own code

A small REST API for embedding the scoring engine in your apps and pipelines.

cURL โ€” Score a URL
# API key required โ€” included with your subscription
curl -X POST https://api.phishfry.ai/v1/score \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "url": "https://my-bank-l0gin.xyz/verify" }'

# Response
{
  "url": "https://my-bank-l0gin.xyz/verify",
  "score": 22,
  "verdict": "danger",
  "signals": [
    "suspicious_tld:.xyz",
    "phishy_keyword:login",
    "tld_embedded_in_subdomain"
  ]
}

Same scoring engine the extensions use, exposed over HTTP. API access is included with every PhishFry subscription.

FAQ

Short answers, no marketing.

The extension protects one browser: URL scoring, scam detector, email banner, report button. Individual and Family plans get the extension. The platform (Business + Enterprise plans) adds org accounts, PhishTest training, sim campaigns, admin dashboard, and the compliance PDF. Same extension binary โ€” the platform features light up when the member's license belongs to an org.

The Chrome extension injects a synthetic message row into the top of the member's Gmail or Outlook inbox โ€” it lives only in the DOM. When they click it, the extension intercepts and opens a "gotcha, this was training" landing page while recording the click. No SMTP, no OAuth, no deliverability risk. Trade-off: works on desktop Chrome only for v1; mobile misses.

Program summary (member count, test coverage, pass rate, avg score, sim delivery / click rate), scam-family accuracy breakdown, per-member training records (sessions, passes, avg score, last-test date, sim outcomes), framework mapping for SOC 2 / HIPAA / PCI-DSS / NIST 800-53 / ISO 27001, and an attestation block for the admin to sign. Print-ready โ€” save to PDF from the browser print dialog.

Yes, on Enterprise. The extension supports Chrome's managed-storage schema โ€” push settings (protection mode, whitelist, custom reporting endpoint, license key) via any of the standard admin channels. Sample policy JSON is in the enterprise docs; contact sales for a walkthrough.

No. URL scoring runs entirely in the browser โ€” URLs never leave the machine. The crowd-intel signals we do collect are k-anonymized (hashed prefixes only, never full URLs). Enterprise customers can point the reporting endpoint at a self-hosted SIEM aggregator to keep telemetry on-premises.

Yes. Any Chromium-based browser (Edge, Brave, Arc, Vivaldi, Opera) can install the Chrome extension directly. Firefox and Safari (macOS + iOS) each have their own build of the same scoring engine.

Individual is $5/month, paid annually โ€” that's the entry price. If cost is a genuine blocker for you (student, non-profit), email sales@phishfry.ai โ€” we do consider comps case by case.

51 in the current taxonomy: 12 BEC families, 14 credential-harvest patterns, 10 financial-fraud variants, 9 malware-delivery types, and 6 social/emotional patterns (sextortion, romance scam, grandparent scam, etc.). The taxonomy ships with the extension and is used by both the real-time detector and the PhishTest training bank.

Stop guessing. Start with a real dashboard.

Business plan starts at $30/month for 10 seats. Two minutes to set up. Cancel anytime.