Attackers now use ChatGPT, Claude, and Gemini to write flawless, personalised phishing emails at industrial scale — and Gmail's spam filter is blind to them. TrustScan is a free Chrome extension that detects AI-generated phishing automatically, right inside your Gmail inbox.
🔒 Privacy-focused · No email content stored · Works in Gmail
Until recently, phishing emails were relatively easy to spot. They arrived with misspelled words, awkward sentence structures, generic salutations like "Dear Valued Customer," and obvious tells — "Congratulations! You have won a prize!" — that any careful reader could recognise. Security awareness training focused on exactly these signals: look for bad grammar, hover over links, check the sender address.
Then large language models went mainstream.
Tools like ChatGPT, Claude, and Google Gemini gave anyone — including criminals — the ability to write persuasive, grammatically flawless prose in seconds. Phishing campaigns that once required a team of native speakers and weeks of refinement can now be produced by a single person in an afternoon. A simple prompt — "write a professional email from a bank telling the customer their account is suspended, make it urgent but reassuring" — produces something indistinguishable from a legitimate bank message to the untrained eye.
The volume exploded alongside the quality. Researchers reported a dramatic surge in AI-assisted phishing campaigns in the twelve months following ChatGPT's public release. The FBI, Interpol, and national cybersecurity agencies across Europe flagged AI-assisted phishing as one of the fastest-growing cybercrime categories. The old detection signals — look for typos, watch for generic greetings — simply stopped working.
What replaced them is AI fighting AI. The same technology that enables attackers to write convincing phishing emails is now used to detect them. TrustScan's AI email scanner applies language-model analysis to every email you receive — checking not just for known patterns, but for the subtle signals of manipulation, deception, and machine authorship that reveal a dangerous email even when the writing is perfect.
Understanding the process is the first step to recognising and resisting it. The workflow is simpler than most people expect, and it scales to thousands of personalised messages per hour.
An attacker starts by selecting a target — often gathered from a data breach, LinkedIn scrape, or public company directory. They identify the target's employer, role, and likely pain points. A financial controller receives a fake invoice approval request. A new employee receives a spoofed IT onboarding email. A small business owner receives a fake payment failure from Stripe or PayPal. The more specific the scenario, the more convincing the output.
The attacker prompts a large language model with a detailed scenario. Skilled attackers use techniques to bypass content safety filters, or use uncensored open-source models with no restrictions at all. A typical prompt might specify the recipient's name, the target company, the desired emotional tone (urgent and official, or warm and friendly), the call to action (click a link, provide credentials, approve a payment), and the impersonated sender (bank, HR department, C-suite executive). The model produces a polished, contextually appropriate email in seconds.
AI tools let attackers merge a base template with specific target data in bulk. They can send thousands of personalised phishing emails — each referencing the recipient by name, mentioning their company, and using contextually appropriate language — in the time it once took to send one. This is "spear-phishing at scale": an attack type that used to require significant research effort per target, now automated completely. Traditional spam filters, which rely on spotting mass-blast patterns, find nothing to flag.
The resulting email has no typos, no obvious spam keywords, and no signature matching anything in a spam database. It arrives from a plausible (though spoofed) domain, carries a believable thread context, and may even reference real public information about the recipient. Standard filters find nothing to block because the email has never been seen before in any form. The only reliable way to detect it is to analyse the language itself — which is exactly what TrustScan does.
Gmail's spam filter is excellent at catching mass-blast spam. But today's threats are targeted, personalised, and written by AI. They slip through because they have no prior signature to match against.
Tools like ChatGPT let attackers write flawless, personalised phishing emails at scale. These don't match any spam signature because they've never been seen before. Only an AI scanner that understands language can catch them — not a blocklist.
Fake invoices, impersonated executives, and fraudulent payment requests land looking completely legitimate. TrustScan's AI scanner sees the urgency manipulation, mismatched sender signals, and social engineering tactics that Gmail ignores.
Scammers attach AI-generated profile photos, fake ID documents, and fraudulent proof-of-payment images. TrustScan scans every image in your Gmail inbox for AI generation artifacts — a capability no standard spam filter offers.
Even as AI-generated phishing becomes harder to detect, certain signals remain. Knowing what to look for lets you pause before clicking — but for reliable protection, you need an automated scanner that catches what the human eye misses.
AI models produce extremely clean, uniform prose. A human sender — even a professional one — will occasionally vary sentence length, use informal phrasing, or show personality. AI-written emails often feel polished to a fault: grammatically flawless, stylistically flat, and strangely impersonal even when they address you by name. If an unexpected email reads like it was written by a meticulous committee, that smoothness is itself a signal.
Modern AI phishing has moved past "Dear Valued Customer" — attackers now include your real name and company. But deeper personalisation is still missing. The email knows who you are but not what you actually do, who you report to, or anything specific about your recent activity. The context is plausible but generic. A real colleague or vendor would reference something concrete.
"Your account will be suspended in 24 hours." "Immediate action required." "Respond before close of business today." AI tools are exceptionally good at generating urgency language because they're trained on millions of examples of it. If an email you weren't expecting carries alarming time pressure, that pressure itself is a red flag — regardless of how professional the writing appears.
The display name says "PayPal Security Team" but the reply-to address is a free Gmail or Outlook account. The sending domain is paypa1.com, paypal-support.net, or paypal.com.support-alerts.io rather than paypal.com. AI models help attackers with writing quality but not with domain infrastructure — the sender address usually shows cracks even when the email body is flawless.
Legitimate emails rarely demand one specific irreversible action under time pressure and with no alternatives offered. "Click this link to verify your identity before your account is permanently deleted" is the structural pattern of phishing, not normal business communication. Real institutions give you time, multiple contact options, and an easy path to verify through their official website rather than the link in the email.
A real colleague won't email about a shared project without referencing something specific. A real bank won't write without mentioning your account type, last transaction, or specific product. AI-generated phishing fills word count with plausible-sounding context but avoids anything that requires insider knowledge — because the attacker doesn't have any. Generic references to "your account," "our records," or "your recent activity" are consistent signals of machine-generated content.
Any unsolicited email asking you to provide login credentials, approve a payment, click through to a login page, download an attachment, or grant access to an account should be treated as suspicious by default — regardless of how professional it looks. AI has made the writing quality of phishing indistinguishable from legitimate email; the only reliable tell left is what the email is trying to get you to do.
Spotting these signals manually requires constant vigilance — and attackers are improving faster than human intuition can adapt. TrustScan checks all seven of these dimensions automatically, for every email you open in Gmail, in under two seconds.
Add to Chrome — FreeThe most effective defence against AI-generated phishing is AI that understands language — not keyword lists. TrustScan applies GPT-based analysis to every email, scoring it across four dimensions simultaneously.
Add TrustScan to Chrome, Edge, or Brave in one click from the Chrome Web Store. It installs directly into Gmail — no separate dashboard to check, no emails to forward, no copy-pasting required. The scanner stays dormant until you open Gmail.
When you open an email, TrustScan automatically submits it for GPT analysis. The model evaluates writing uniformity and AI-authorship signals, phishing threat indicators, scam and fraud patterns, social engineering language (urgency, authority impersonation, emotional pressure), and any attached images for AI-generation artifacts. This happens in parallel — you don't wait for separate checks.
TrustScan scores each email across four dimensions: phishing risk, scam risk, overall threat level, and AI-authorship likelihood. These four scores are combined into a single 0–100 trust score. The result appears as a traffic-light badge — green, amber, or red — directly in your Gmail view. Email content is discarded immediately after scoring; nothing is stored.
On the Smart plan, TrustScan goes beyond detection. When a high-risk email is identified, it actively neutralises threats by auto-disabling risky links and masking suspicious content — removing the danger before you can accidentally interact with it. Basic gives you the warning; Smart removes the risk entirely.
Credential theft, fake login pages, urgent account-suspension threats, and links designed to steal passwords or personal information — including novel AI-generated variants with no prior signature.
Emails written by ChatGPT, Claude, Gemini, or similar AI tools — identified by writing uniformity, grammar patterns, structural signals, and the telltale absence of personal quirks.
Fake invoices, lottery scams, romance fraud, advance-fee scams, and impersonation of banks, couriers, or government agencies — including AI-assisted variants designed to bypass conventional filters.
Manipulation tactics including false urgency, authority impersonation, fear induction, and emotional pressure designed to make you act without thinking. AI tools are especially effective at generating these patterns at scale.
AI-generated profile photos, forged documents, and fake proof-of-payment images attached to emails to establish false credibility. TrustScan scans every image for generation artifacts.
Executive impersonation, vendor fraud, and payment-redirect scams targeting professionals via Gmail. AI makes these attacks far easier to craft and far harder to spot manually.
Every email gets a score from 0–100 based on AI-authorship signals and threat risk, powered by GPT. Four dimensions are evaluated in parallel and combined into a single badge you see inside Gmail.
No significant phishing, scam, or AI-threat signals detected. Looks safe to read and act on.
Some risk signals present. Verify the sender and be careful with links, attachments, and any requests in this email.
High likelihood of phishing, scam, or fraud. Do not click links, download attachments, or share any information.
Scores are generated fresh for every email you open. Email content is discarded immediately after scoring — never stored permanently.
AI-generated phishing emails are not only sent to large corporations with dedicated security teams. Because the production cost is now nearly zero, attackers can afford to target anyone. Some groups face elevated risk.
Finance controllers, accounts payable staff, and freelancers who receive regular invoice and payment requests are the primary targets of AI-assisted business email compromise. A single convincing fake invoice can redirect a wire transfer.
C-suite and senior staff are targeted with "CEO fraud" — AI-written urgent messages impersonating executives, requesting gift cards, wire transfers, or sensitive data from subordinates. The authority signal combined with urgency is particularly effective.
Small businesses lack dedicated IT security and are targeted with spoofed supplier messages, fake platform notifications (Stripe, Shopify, QuickBooks), and impersonation of government agencies. AI makes these attacks far more convincing than they once were.
Public profiles give attackers the raw data needed to personalise AI-generated phishing. Your job title, employer, recent activity, and professional connections are all inputs that make a phishing email harder to dismiss as generic spam.
AI-generated phishing emails are fraudulent messages written using large language models such as ChatGPT, Claude, or Gemini. Unlike traditional phishing that relies on broken English and generic greetings, AI-generated phishing is grammatically flawless, contextually plausible, and often personalised with the recipient's real name and employer. Because these emails have no prior signature, traditional spam filters cannot identify them. The effective countermeasure is language-based AI analysis — the same class of technology used to create them.
Yes. The most effective approach is AI fighting AI. TrustScan uses GPT to analyse each email for phishing signals, scam indicators, social engineering patterns, and AI-authorship signals simultaneously. Because the analysis is language-based rather than signature-based, it catches novel AI-generated phishing emails that have never been seen before — including ones that bypass Gmail's spam filter entirely. The result is an instant 0–100 trust score displayed inside Gmail without any copy-pasting.
Yes. TrustScan is free to install and includes 50 free scans per month — enough for most personal Gmail users. No credit card required. Paid plans start at $5/month for higher scan volumes. See the pricing page for details.
Gmail's spam filter blocks mass-blast campaigns based on known patterns and blocklists. TrustScan's AI email scanner understands language using GPT — it reads the actual content of each email to detect targeted phishing, AI-generated scam messages, social engineering tactics, business email compromise, and deepfake images. These threats are personalised and novel, so they have no signature for Gmail to match against. TrustScan adds a second layer of protection specifically for the threats Gmail misses.
No. TrustScan never permanently stores your email content. When you open an email in Gmail, the text is sent for analysis, a trust score is generated, and the content is immediately discarded. TrustScan does not log, sell, or share email content. Read our privacy policy for full details.
Yes. TrustScan is specifically built to detect emails written by ChatGPT, Claude, Gemini, and similar large language models. It analyses writing style uniformity, grammatical patterns, sentence structure, and other signals that distinguish machine-generated text from human writing. This matters because attackers increasingly use AI to write convincing phishing and scam emails at scale — emails with perfect grammar that bypass every traditional filter.
TrustScan uses OpenAI's GPT model to analyse each email. GPT understands natural language context, which means it can identify manipulation tactics, urgency language, impersonation patterns, and AI-authorship signals that keyword-based scanners miss entirely. The model scores four dimensions per email — phishing risk, scam risk, overall threat level, and AI-authorship likelihood — and combines them into a single 0–100 trust score.
No, you do not need a separate tool. TrustScan combines AI email scanning with dedicated email phishing detection in a single extension. Every scan checks for AI-authorship signals and phishing threat indicators simultaneously — you get full coverage in one badge, inside Gmail, with no extra steps.
AI-generated phishing is getting better every month. Get an AI scanner that keeps up — automatically, inside Gmail, for free.
Install TrustScan for ChromeRequires Google Chrome, Edge, or Brave. No account needed · Uninstall anytime.