We take the bite so you don't.

Forward any sketchy email to bite@bait.sh. We open every link and file in a sealed sandbox, screenshot where it really goes, and tell you in plain English what it wants from you.

See a sample report

Private beta. Invite only for now.

bait.sh sandbox

Example check of a sketchy email:

  1. received: "Your package is on hold"
  2. link 1: following 4 redirects...
  3. landed on: parcel-redelivery-help[.]top
  4. page asks for: card number
  5. screenshot saved
  6. verdict: HOOKED

How it works

  1. 1. Forward it.

    Send anything sketchy to bite@bait.sh.

  2. 2. We bite.

    We open every link and file in a sealed sandbox, so you don't have to.

  3. 3. You get the catch.

    A plain-English report in minutes: where it goes, what it wants, what to do.

Tip: forward as an attachment for the most detailed report.

What we check

The verdict

Not just email. Anything sus.

Email is just the start. Soon you'll be able to send us anything that looks like bait.

Sample report

See a sample report

HOOKED

This is a fake delivery notice that sends you to a card-stealing page.

Pretends to be
ParcelDash delivery
Wants
Your card number
Really goes to
parceldash-redelivery[.]example

FAQ

Who can use it?

Right now it's a private beta, invite only.

Do you actually click the links?

Yes, inside a sealed sandbox that's thrown away after every check. Nothing touches your device.

Is my email private?

We keep the email for 7 days and the report for 30, then delete them. No ads, no selling data, no ad trackers.

Is it 100% accurate?

No tool is. bait.sh catches a lot, but when in doubt, don't click.

Want in?