Modern phishing is AI-written, pixel-perfect, and lands from senders you recognize. PhishFry blocks the bad clicks at the browser, catches BEC and wire-fraud pretexts before they land, trains your team with a 1,160-email inbox simulator, and hands your auditor a print-ready SOC 2 report. One product, two audiences.
The extension protects every user's browser. The platform gives admins the training and audit story they need. Pick the parts you want.
Roll out the extension to every laptop via MDM or your admin console. Enroll members into an org account, set a training cadence, turn on simulated phishing, and watch the admin dashboard fill in.
If you just want a browser that flags the bad links and warns you before you enter a password into a lookalike, that's what the free-agent side of PhishFry is for. Optional family plan covers up to four people.
Six pillars, one product, two surfaces (browser + admin dashboard).
Extension scores every link before it's clicked. Lookalike domains, suspicious TLDs, freshly-registered traps, brand impersonation โ scored 0-100 locally, no URLs leaving your machine.
A 50+ scam taxonomy (BEC, credential harvest, financial fraud, malware delivery, social/emotional) catches the pretext side โ gift-card asks, wire-fraud, sextortion โ even when no URL is malicious.
PhishTest is a Gmail-clone inbox with 1,160 curated emails (500+ phish across ~250 brands). Members retake in fresh batches โ no repeats until they've cycled through every batch.
Turn on sim campaigns and the extension injects one fake phish into each member's Gmail or Outlook inbox on your cadence. Click โ "gotcha, this was training." No SMTP, no deliverability risk.
One-click "Report to PhishFry" button in the Gmail / Outlook toolbar. Every submission lands in the org dashboard with sender + subject + top-domain rollup. Turns every user into a sensor.
Print-ready training-evidence report an auditor accepts. Covers SOC 2 CC1.4 / CC5, HIPAA 164.308(a)(5), PCI-DSS 12.6, NIST 800-53 AT-2, ISO 27001 A.7.2.2 in one document.
It's not Nigerian-prince emails anymore. Modern phishing is AI-written, pixel-perfect, and shows up in your inbox from sender addresses you've seen a hundred times.
These are the patterns PhishFry catches and trains against.
Zeros for o's, ones for l's, swapped letters. Brand-impersonation check tanks the score before the hover tooltip finishes drawing.
Modern BEC uses your real CEO's name, a freemail sender, and a "sent from my iPhone" signature. Scam detector flags exec-name + freemail-domain + urgency in one pass.
Package-redelivery scams are the #1 SMS/email fraud in the US. Callback (TOAD) scams that ask you to phone a number to "dispute a charge" are second. Both are in the taxonomy.
Fake Coinbase / MetaMask / Ledger emails asking for seed phrases. Critical single-signal trigger โ one hit and the warning banner fires.
Real (or compromised) vendor sends an invoice asking payment to a new bank account. Highest-loss BEC category. Detector flags "new bank account" + digit-run + urgency.
Fake "shared with you" notification from a wrong sender. Extension unwraps Gmail + Outlook SafeLinks wrappers so we score the real destination.
Install the extension. That's it. It just works in the background.
Every <a> tag on every page gets a score. Green (80+)
means safe, amber (50โ79) means caution, red (below 50) means don't click.
Scores of 90+ hide their tooltip so clean pages don't get noisy.
Gmail and Outlook web get a warning banner when the message matches a scam-taxonomy pattern. The banner names the family (CEO wire, credential harvest, package undeliverable) and gives the safe action verbatim.
One dashboard. Every visibility gap a security lead usually has to piece together from three tools.
service@paypa1-alerts.com โ "Your account has been limited" โ sim โorders@amaz0n-billing.com โ "iPhone order confirmation โ $1,299"refunds@irs-refund.us โ "Tax refund pending"paypa1-alerts.com ยท docusign-secure.co ยท usps-track-notice.info1,160 hand-curated emails across ~250 brands, grouped into 58 batches of 20. Members retake the test in fresh batches โ no repeats until they've cycled through the whole bank.
Every phish carries a taxonomy tag (BEC, credential harvest, financial fraud, malware delivery, social/emotional). The admin heatmap shows which categories your team gets wrong, so training focuses on the actual weak spots.
KnowBe4-style training-in-real-inboxes, with none of the deliverability wars. The Chrome extension injects one fake phish per member into their Gmail or Outlook inbox on your cadence. Click โ "gotcha, this was training" page.
Pick a cadence (weekly / bi-weekly / monthly). Optionally target specific scam families (BEC only for finance, credential-harvest only for devs).
Next time each member opens Gmail or Outlook, the extension adds one synthetic row to the top of the inbox. Looks native. No email actually sent.
Click โ landing page reveals it was training. Hit Report โ counts as a save. Ignore for 48h โ recorded. Admin dashboard shows per-member results.
Why the extension does the injection: no SMTP means no risk of a legit training email landing in spam, no sender-reputation damage, no OAuth scopes to audit. Trade-off: desktop Chrome-in-Gmail/Outlook only for v1.
Every framework wants the same thing: proof you train your workforce regularly and measurably. PhishFry generates that proof on demand.
CC1.4, CC5 โ documented, ongoing security-awareness training for all workforce members.
164.308(a)(5) โ per-employee completion records + ongoing training program evidence.
12.6 โ annual (or more frequent) security awareness training with measured effectiveness.
AT-2 โ role-based training records with measurable outcomes per member.
A.7.2.2 โ formal awareness program with employee-level records.
Admin hits "Open report" on /org/admin. Browser prints the report to PDF. Auditor gets what they asked for. Sales cycle shrinks.
Six-plus signals, combined into a 0โ100 number you can read at a glance.
.gov, .edu, and .mil score high. Frequently abused TLDs like .tk, .xyz, and .gq score low.
Tranco top-500K, Umbrella top-1M, and Cloudflare Radar combined. Domains the world already trusts get a boost.
Phishy keywords (login, verify, secure), embedded TLDs, long numeric runs, urgency words. Path signals beyond the hostname.
RDAP lookup for registration date + CT-log-derived cert-age bloom. Brand-new domains score down; long-lived indie sites get a modest boost.
PhishTank + OpenPhish + Netcraft + URLhaus, refreshed weekly. Bundled snapshot ships with the extension so day-zero users are covered.
Site owners can verify ownership via meta tag or DNS TXT and earn a score boost.
Type a URL โ real or phishy โ and see how it scores. Runs entirely in your browser.
The demo uses a simplified subset of the scoring engine. The installed extension factors in the popularity union, RDAP domain age, CT-log cert age, threat-feed union, and the scam-detector taxonomy on top of what you see here.
Prove your domain is yours with a meta tag or DNS TXT record. Verified sites get a green checkmark in tooltips + a +15 score boost. Free.
<meta name="phishfry-verified" content="YOUR_TOKEN">
_phishfry.example.com TXT "phishfry-verify=YOUR_TOKEN"
Extension is the same on every plan. Higher tiers add the platform: training, sims, admin dashboard, compliance report.
Extension for one person.
Paid annually ยท $60 / year
Extension for the household.
Paid annually ยท up to 4 users
Extension + training + admin dashboard.
10 users ยท $3/user for more
Managed rollout at scale.
Custom pricing ยท 100+ users
A small REST API for embedding the scoring engine in your apps and pipelines.
# API key required โ included with your subscription
curl -X POST https://api.phishfry.ai/v1/score \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "url": "https://my-bank-l0gin.xyz/verify" }'
# Response
{
"url": "https://my-bank-l0gin.xyz/verify",
"score": 22,
"verdict": "danger",
"signals": [
"suspicious_tld:.xyz",
"phishy_keyword:login",
"tld_embedded_in_subdomain"
]
}
Same scoring engine the extensions use, exposed over HTTP. API access is included with every PhishFry subscription.
Short answers, no marketing.
The extension protects one browser: URL scoring, scam detector, email banner, report button. Individual and Family plans get the extension. The platform (Business + Enterprise plans) adds org accounts, PhishTest training, sim campaigns, admin dashboard, and the compliance PDF. Same extension binary โ the platform features light up when the member's license belongs to an org.
The Chrome extension injects a synthetic message row into the top of the member's Gmail or Outlook inbox โ it lives only in the DOM. When they click it, the extension intercepts and opens a "gotcha, this was training" landing page while recording the click. No SMTP, no OAuth, no deliverability risk. Trade-off: works on desktop Chrome only for v1; mobile misses.
Program summary (member count, test coverage, pass rate, avg score, sim delivery / click rate), scam-family accuracy breakdown, per-member training records (sessions, passes, avg score, last-test date, sim outcomes), framework mapping for SOC 2 / HIPAA / PCI-DSS / NIST 800-53 / ISO 27001, and an attestation block for the admin to sign. Print-ready โ save to PDF from the browser print dialog.
Yes, on Enterprise. The extension supports Chrome's managed-storage schema โ push settings (protection mode, whitelist, custom reporting endpoint, license key) via any of the standard admin channels. Sample policy JSON is in the enterprise docs; contact sales for a walkthrough.
No. URL scoring runs entirely in the browser โ URLs never leave the machine. The crowd-intel signals we do collect are k-anonymized (hashed prefixes only, never full URLs). Enterprise customers can point the reporting endpoint at a self-hosted SIEM aggregator to keep telemetry on-premises.
Yes. Any Chromium-based browser (Edge, Brave, Arc, Vivaldi, Opera) can install the Chrome extension directly. Firefox and Safari (macOS + iOS) each have their own build of the same scoring engine.
Individual is $5/month, paid annually โ that's the entry price. If cost is a genuine blocker for you (student, non-profit), email sales@phishfry.ai โ we do consider comps case by case.
51 in the current taxonomy: 12 BEC families, 14 credential-harvest patterns, 10 financial-fraud variants, 9 malware-delivery types, and 6 social/emotional patterns (sextortion, romance scam, grandparent scam, etc.). The taxonomy ships with the extension and is used by both the real-time detector and the PhishTest training bank.
Business plan starts at $30/month for 10 seats. Two minutes to set up. Cancel anytime.