Phishing Reporter // AI analysis

Employees report.
KeenSec AI investigates.

Employees report a suspicious email in one click, right in the inbox they already use. KeenSec checks it against multiple threat-intelligence and reputation sources and explains the verdict in plain language, in seconds.

KeenSec Shield

Every report, analysed.
Every verdict explained.

Sender, links, attachments and wording, checked together, so your team knows what to do next.

● One-click reporting ● Link and attachment checks ● Plain-language verdicts
KEENSEC // SAMPLE REPORTED EMAIL SAMPLE DATA
HEADERS Captured in full Nothing lost to forwarding
ROUTING HOPS 4 Relays Sent via an anonymising relay
SAMPLE MESSAGE HEADERS REPORT BUTTON
Received: from mail-out.attacker-c2.net (185.220.101.42)
From: "Sarah Jenkins, CFO" <s.jenkins@attacker-c2.net>
Reply-To: executive-wire@secure-fin-wire.com
Subject: URGENT: Wire Transfer Authorization #99218

Try the triage demo

Pick a reported email.
See the evidence.

See how Phishing Reporter weighs the signals, spots contradictions and shows its confidence.

Interactive sample. All names and data are illustrative.
REPORTED MESSAGE Reported by: David Miller (Finance)
Subject: URGENT: Revised Banking Details for Northstar Invoice #8849
From: Sarah Jenkins <s.jenkins@northstar-invoices.example>
To: david.miller@enterprise.com
Reporter Note: "Sarah usually calls me before changing payment accounts. This invoice arrived with an unfamiliar IBAN."
Signals checked
SPF / DKIM AUTH SPF: Pass | DKIM: Pass Sender authenticated for external domain
DOMAIN AGE Age: 4 Days Old Registered 2026-09-19, owner hidden
REDIRECT HOPS 3 Redirect Hops Final URL: payment-auth-gateway.top
ATTACHMENT / PAYLOAD PDF (Active Hyperlink) No known-bad file matches
HISTORICAL REPUTATION First-Time Sender No previous mail from this sender
REPORTER TRACK RECORD 94% Historical Precision Reporter has correctly flagged 16/17 lures
VERDICT & REASONING CRITICAL THREAT
Confidence 98.4% Confidence

What we found

Impersonation: The name says CFO Sarah Jenkins, but the mail came from lookalike domain northstar-invoices.example.
Brand-new domain: Registered 4 days ago, with no history in your organisation.
Payment pressure: Urges a wire to an unfamiliar offshore account.
Contradiction: Sender checks pass because the attacker owns the domain. Passing them does not make the message safe.

Recommended next steps

How it works

From report to verdict in four steps

Seconds from an employee's report to an explained verdict, with your analysts in charge.

Stage 01

One-click report

One click, right in the inbox your people already use. The full message and the employee's note come with it.

  • Full message kept intact
  • Employee's concern captured
Stage 02

Automatic checks

Sender, links and attachments are checked against multiple threat-intelligence and reputation sources.

  • Known-bad link lists
  • File and link reputation
  • Sender network location
Stage 03

Connecting the clues

AI weighs the signals together and spots contradictions, like a passing sender check on a days-old lookalike domain.

  • Urgency and pressure spotted
  • Contradictions flagged
Stage 04

Explained verdict

Analysts get a plain-language summary, a confidence rating and recommended next steps. They make the final call.

  • Clear confidence rating
  • Analyst sign-off

What gets checked

Six signals behind every verdict

Every report is checked from six angles, so less slips through.

01 Sender

Sender and header checks

Spots display-name spoofing, mismatched return paths and forged sender details.

Why it matters: Reporting in the inbox keeps headers that forwarding strips.
02 Links

Links, followed to the end

Follows shortened links and redirects to the final page, then checks it against known-bad link lists.

Why it matters: You see where a link really lands.
03 Attachments

Attachment checks

Looks for risky macros and hidden scripts, and checks file reputation across multiple sources.

Why it matters: Risky files are flagged for your analysts.
04 Domain Age

New and lookalike domains

Checks how new a domain is and how closely it imitates your own brand.

Why it matters: Brand-new domains get extra suspicion.
05 Intent

Pressure and intent

AI spots urgency, executive impersonation, payment pressure and fake sign-in requests.

Why it matters: Intent is mapped to MITRE ATT&CK tactics.
06 Reporter

Reporter track record

Reports from people with an accurate track record rise to the top.

Why it matters: Your team sees the most credible reports first.
Reported email queue. Every report lands in one queue with a verdict and the reasons behind it.

At a glance

Key facts about Phishing Reporter analysis

Explore Trust Center
CAPABILITY OVERVIEW

What is it?

The analysis side of Phishing Reporter. Employees report in one click, right in the inbox they already use, and every report is analysed automatically.

PROBLEM SOLVED

What problem does it solve?

Security teams get flooded with reports, many of them false alarms or simulations. Checking each one by hand is slow.

INFORMATION INPUTS

What gets checked?

Sender, headers, domain age, links, attachments and the employee's note, against multiple threat-intelligence and reputation sources.

HUMAN GOVERNANCE

Where does the human remain in control?

Your analysts decide every response, such as removing messages or blocking a domain.

PLATFORM CONNECTION

How does it connect across KeenSec?

Real threats people report can inspire new simulations in AI Studio, and reporting speed feeds Human Risk Analytics.

Let’s connect the dots

Turn every report into
an explained verdict.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo