AI-Powered Phishing & Malware Scanner

Phishing is written with AI now — scan it with AI too. Upload suspicious email, HTML, PDF, Office, or installer files. One free scan per account per day. Or forward to [email protected].

Upload a suspicious file

Drop a saved email (.eml, .msg), web page, PDF, Office file (.docx, .xlsx), calendar invite (.ics), or installer (.exe, .dmg, .apk, .msi, .deb). The AI verdict appears on this page.

Or forward by email

Forward a suspicious message to [email protected]. RookScan replies with the AI verdict — useful when you cannot access a browser safely.

One scan per day — free

Each signed-in account gets one free scan per day. The daily limit applies both to the web upload and the [email protected] email forwarding address.

How this page is different

AI-Powered Phishing & Malware Scanner exists to paste a suspicious email, link, or PDF and read the signals before you click or forward it. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.

Do this on the page

Work through AI-Powered Phishing & Malware Scanner in order. 1. Choose email, link, or PDF to match what you actually received. 2. Submit the content and read each signal, not only a single score. 3. Do not click the original link while you are still reading the report. 4. Forward the report, not the raw lure, if you need a second opinion. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.

What this page will not decide for you

A scanner is not a guarantee the message is safe or malicious. It does not remove a payload from your inbox. Links should be checked as text, not opened first. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.

A concrete example

Example: an email says a mailbox is full and the link host is a lookalike domain. The report flags the domain and the urgency. You do not click. You open the real provider by typing the address yourself. If the report is inconclusive, you still do not use the link from the message.

Where to go next

After you finish AI-Powered Phishing & Malware Scanner, open the phishing email page or the link checker depending on what arrived if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.

If you only remember one thing

Use AI-Powered Phishing & Malware Scanner for one job: to paste a suspicious email, link, or PDF and read the signals before you click or forward it. Bring the before-and-after evidence with you if you change a setting. A VPN icon, a decoded token, a generated password, or a stripped file is not finished until you have checked the output the way this page describes. Then follow the related guide for the long version, and the sibling tool only when the next job is actually different. Keep secrets out of the same message as the link or the file that needs them. If a second run does not match the first, stop and find what changed instead of publishing the first result.

Field notes

Example: an email says a mailbox is full and the link host is a lookalike domain. The report flags the domain and the urgency. You do not click. You open the real provider by typing the address yourself. If the report is inconclusive, you still do not use the link from the message. Work the page in this order: Choose email, link, or PDF to match what you actually received. Submit the content and read each signal, not only a single score. Do not click the original link while you are still reading the report. Forward the report, not the raw lure, if you need a second opinion. Limits that still apply after a clean result: A scanner is not a guarantee the message is safe or malicious. It does not remove a payload from your inbox. Links should be checked as text, not opened first.

Frequently asked questions

Is RookScan free?

Yes. One scan per signed-in account per day is free at rookvpn.com/scan. Forwarding to [email protected] is also limited to one result per sender per day.

What AI model analyzes the scan?

RookScan uses a large language model to analyze file structure, content, embedded links, and behavioral indicators for phishing and malware signatures.

Do you keep the original file?

Scan artifacts are retained only for a short operational window then removed. Do not upload messages or files you are not comfortable sharing with an automated scanner.

What file types can I scan?

Supported: .eml, .msg, .html, .htm, .pdf, .docx, .xlsx, .pptx, .ics, .exe, .dmg, .apk, .msi, .deb, and URL shortcut files.

Do I paste the whole email?

Yes, including headers if you have them. The links are the part that matters most.

Will this click the link for me?

The checker inspects the URL. Do not open it yourself while you wait.

Email scanner guide One-time secret link Remove photo metadata
Scan Email [email protected] VPN Leak Test Remove EXIF