Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.

Baitwall · Gmail add-on for phishing detection

Your employees already spot it. Give them one button.

Baitwall puts a scored verdict in the Gmail sidebar and a report in your security team's inbox — in under three seconds, without ever storing the email.

2.9s
Median verdict
4
Threat levels
0
Bodies stored
Analyzing message2.9s

From

"Microsoft Account Team" no-reply@micros0ft-account.com

Lookalike domain — 0 substituted for o

Reply-to

inbox@ms-verify.xyz

Reply host does not match sender domain

Link

http://ms-verify.xyz/login

Credential form on an unrelated host

Body

“…verify your identity within 12 hours”

Urgency paired with account-lockout threat

Verdict

96Phishing

4 indicators

Body discarded after analysis — never written to disk

01 · The loop

Report, score, alert. Nothing else to learn.

No new app, no training program, no rules to maintain. The add-on lives in the message the employee is already looking at.

Baitwall

🚨 Critical Threat

Threat Analysis

Phishing Score

96% likely phishing

Phishing

Threat Indicators

  • Lookalike domain — micros0ft-account.com
  • Link host does not match sender
  • Urgency: “within 12 hours”
  • Threat of account lockout
Report phishing

Body discarded after analysis

The sidebar card, as the employee sees it.

  1. 01

    Employee opens a message, presses Analyze

    Nothing is scored until they ask. One click checks sender, reply-to, links, headers, and language, and explains the verdict in plain English.

  2. 02

    They press Report phishing

    One button. The verdict, indicators, and metadata are filed against your tenant; the body is discarded the moment analysis returns.

  3. 03

    Security gets the alert and the trail

    A formatted alert reaches your security inbox, and the report lands in the dashboard with a status you can work through.

02 · The dashboard

What your security team sees on Monday morning.

Open a workspace

Reports · Today

5 new
TimeSenderScoreStatus
09:42

Unusual sign-in activity detected

no-reply@micros0ft-account.com

96Escalated
09:17

Invoice #40118 is 14 days overdue

billing@dropbox-invoice.co

81Reviewed
08:55

Action required: re-enroll by Friday

hr-portal@acme-benefits.net

64New
08:31

Q3 partner pricing is live

deals@newsletter.vendorhub.io

22Dismissed
08:04

Your deployment finished

notifications@github.com

4Dismissed

Reports · 30 days

+34%

312

reports filed across 4 domains

30d agopeak 26 · Aug 3today

2.9s

Median verdict time

96

Avg score, escalated

0

Email bodies stored

Every figure is scoped to your tenant. Reports carry a status — new, reviewed, escalated, dismissed — so the queue drains instead of growing, and filters cut by category, score floor, and date range.

03 · Scoring

A number, a category, and the reason for both.

Scores are useless without the why. Every verdict returns the specific indicators that produced it, so an analyst can agree or overrule in seconds.

80 — 100

Critical

Credential harvest, lookalike domain, payment redirect.

Escalate
60 — 79

High

Multiple indicators, sender inconsistent with content.

Review
40 — 59

Medium

One strong signal, weak corroboration — worth a second look.

Triage
0 — 39

Low

Sender, links, and intent check out — at worst, ignorable noise.

Close

POST /api/reports · 201

2.9s
{
  "reportId": "7a67e273-a1bf-477f-a5b8",
  "score": 96,
  "category": "phishing",
  "indicators": [
    "Lookalike domain: micros0ft-account.com",
    "Link host mismatch: ms-verify.xyz",
    "Urgency language: 'within 12 hours'",
    "Threat of account lockout"
  ],
  "summary": "Impersonates Microsoft with a
    lookalike sender and a non-Microsoft link…"
}

Same payload the Gmail card renders and the alert email formats. One verdict, three surfaces.

Set it up before your next coffee.

Create a workspace, copy the API key into the add-on, deploy it org-wide. No infrastructure to run.