Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.
Baitwall · Gmail add-on for phishing detection
Baitwall puts a scored verdict in the Gmail sidebar and a report in your security team's inbox — in under three seconds, without ever storing the email.
From
"Microsoft Account Team" no-reply@micros0ft-account.com
Lookalike domain — 0 substituted for o
Reply-to
inbox@ms-verify.xyz
Reply host does not match sender domain
Link
http://ms-verify.xyz/login
Credential form on an unrelated host
Body
“…verify your identity within 12 hours”
Urgency paired with account-lockout threat
Verdict
96Phishing
4 indicators
Body discarded after analysis — never written to disk
01 · The loop
No new app, no training program, no rules to maintain. The add-on lives in the message the employee is already looking at.
Baitwall
🚨 Critical Threat
Threat Analysis
Phishing Score
96% likely phishing
Phishing
Threat Indicators
Body discarded after analysis
The sidebar card, as the employee sees it.
Nothing is scored until they ask. One click checks sender, reply-to, links, headers, and language, and explains the verdict in plain English.
One button. The verdict, indicators, and metadata are filed against your tenant; the body is discarded the moment analysis returns.
A formatted alert reaches your security inbox, and the report lands in the dashboard with a status you can work through.
02 · The dashboard
Reports · Today
5 new| Time | Sender | Score | Status |
|---|---|---|---|
| 09:42 | Unusual sign-in activity detected no-reply@micros0ft-account.com | 96 | Escalated |
| 09:17 | Invoice #40118 is 14 days overdue billing@dropbox-invoice.co | 81 | Reviewed |
| 08:55 | Action required: re-enroll by Friday hr-portal@acme-benefits.net | 64 | New |
| 08:31 | Q3 partner pricing is live deals@newsletter.vendorhub.io | 22 | Dismissed |
| 08:04 | Your deployment finished notifications@github.com | 4 | Dismissed |
Reports · 30 days
+34%312
reports filed across 4 domains
2.9s
Median verdict time
96
Avg score, escalated
0
Email bodies stored
Every figure is scoped to your tenant. Reports carry a status — new, reviewed, escalated, dismissed — so the queue drains instead of growing, and filters cut by category, score floor, and date range.
03 · Scoring
Scores are useless without the why. Every verdict returns the specific indicators that produced it, so an analyst can agree or overrule in seconds.
Critical
Credential harvest, lookalike domain, payment redirect.
High
Multiple indicators, sender inconsistent with content.
Medium
One strong signal, weak corroboration — worth a second look.
Low
Sender, links, and intent check out — at worst, ignorable noise.
POST /api/reports · 201
2.9s{
"reportId": "7a67e273-a1bf-477f-a5b8",
"score": 96,
"category": "phishing",
"indicators": [
"Lookalike domain: micros0ft-account.com",
"Link host mismatch: ms-verify.xyz",
"Urgency language: 'within 12 hours'",
"Threat of account lockout"
],
"summary": "Impersonates Microsoft with a
lookalike sender and a non-Microsoft link…"
}Same payload the Gmail card renders and the alert email formats. One verdict, three surfaces.
Create a workspace, copy the API key into the add-on, deploy it org-wide. No infrastructure to run.