← All projects

01 / CASE STUDY

Phishing email analysis

Explainable email triage without opening a link.

Open offline demo →

Developed with AI coding assistance; validated through documented automated tests. I defined the project goals and reviewed the delivered results. AI agents assisted with implementation and executed the documented automated tests.

Actual phishing email analysis interface with a fictional training sample
Real Firefox screenshot · fictional bundled data only.

Challenge

Inspect suspicious email without visiting its links or treating a score as a verdict.

Environment

Dependency-free HTML, CSS and JavaScript running locally in browser memory. Six fictional reserved-domain examples.

Built

A deterministic weighted-rule engine, family caps and an evidence ledger. Checks include pressure, sensitive requests, link mismatch, attachment filenames and reported authentication headers.

Tested

The existing project reports 22 engine tests and 17 real DOM checks at both desktop and mobile widths. The portfolio verifies the copied engine and demo controls again; current results are retained in private evidence.

Concepts

Heuristic detection, explainability, authentication uncertainty and independent verification.

Outcomes

The obvious-phishing fixture scores 95; the legitimate-style notice scores 0. The parcel-fee example scores 19, demonstrating that low indicators does not mean safe.

Takeaways

A visible rule ledger makes scoring inspectable. Negative examples and missed-scam examples expose the boundaries better than a polished score alone.

Limitations

Not a malware scan, reputation lookup or calibrated probability. Pasted headers can be forged; plain text can hide destinations. No DNS or redirect checks.