Every scam works the same way: a button that doesn't say where it takes you. Stonephish labels every link in your email with its true destination — before you click — and flags the ones pretending to be someone they're not.
"Verify your account." "Track your package." "Claim your reward." You can't see where any of them go — and that's the entire trick. Stonephish takes the blindfold off.
Each link gets its real destination printed next to it: Claim your reward → 557898302.com. Nothing hidden, nothing to hover over.
One chip at the top: 8 links → 4 sites · 2 to check. Open it and you see every destination in the email, worst first.
"Instagram" writing from a random address gets caught. Stonephish knows the real sending domains of 75+ commonly-faked brands.
This live demo runs a sample of Stonephish's checks right in your browser. Nothing you type is sent anywhere.
No mail client tells you where a button goes. And Google Safe Browsing is a blocklist — it only knows about scams someone already reported. Most phishing sites live less than a day and do their damage in the first few hours, before any list catches up.
| Protection | Google Safe Browsing | Stonephish |
|---|---|---|
| Shows where each link goes, before you click | ✗ No | ✓ On every link |
| Lists every destination in a message | ✗ No | ✓ One click |
| Blocks known, already-reported scam sites | ✓ Yes | ✓ Yes (roadmap: layered on top) |
| Catches brand-new sites registered days ago | ✗ Not until reported | ✓ Yes — domain age & structure analysis |
| Detects lookalike domains (arnazon, paypa1…) | ✗ No | ✓ Yes |
| Flags fake sender names in your inbox | ✗ No | ✓ Yes |
| Explains each warning in plain English | ✗ Generic warning page | ✓ Every reason, spelled out |
Seniors lost $7.7 billion to online fraud last year. Stonephish was designed so anyone — your parents, your grandparents, you at 11pm — can see danger instantly, without needing to be a security expert.
Image buttons, "click here", tracking redirects — all of them show their true address. The one habit that stops most scams.
Judges links it has never seen before using domain age, lookalike spelling, redirect chains, and 20+ other signals. No blocklist required.
Knows the real sending domains of 75+ most-impersonated brands. "Wells Fargo" from a gmail address never gets past it.
Most tools call anything "safe" by default. Stonephish only shows green when the address proves who the sender is — otherwise it says so.
It notes every unsubscribe link it passes. Tick the lists you're done with and Stonephish opens each one for you — refusing outright any it has flagged as unsafe.
No server, no account, no network requests at all. Every check runs in your browser and is then forgotten. There is nothing to upload, so nothing is uploaded.
Stonephish is free because the people most likely to be targeted are the least likely to pay for security software.