Inspiration

Email phishing and financial fraud have evolved past crude, poorly-worded messages into highly sophisticated, targeted social engineering attacks. Cybercriminals routinely spoof trusted corporate domains, mimic transactional alerts, and deploy zero-day malicious links that bypass traditional static blocklists. We were inspired to build PhishGuard AI to level the playing field—giving everyday users and organizations an intelligent, real-time shield that reads between the lines of incoming emails to catch threats before damage is done.

What it does

PhishGuard AI is an automated email fraud and phishing detection system that analyzes incoming messages for hidden malicious intent. Key features include:

  • Natural Language Threat Analysis: Scans email body text and headers for urgent language, coercive psychological triggers, and brand impersonation patterns.
  • URL & Attachment Safety Checks: Inspects embedded links and metadata to flag redirect chains, typosquatting domains, and unauthorized payloads.
  • Risk Scoring & Explanations: Assigns a clear threat level (Safe, Suspicious, Malicious) along with a breakdown of why an email was flagged so users can learn to spot threats.

How we built it

  • Backend: Built using Python with a robust API framework to process incoming emails and manage scoring pipelines.
  • AI & Detection Logic: Integrated advanced language understanding models to classify sentiment, detect urgency manipulation, and identify domain anomalies.
  • Frontend / UI: Developed a responsive web dashboard where users can view analysis reports and scan logs in real-time.

Challenges we ran into

  • Balancing Latency and Accuracy: Deep semantic analysis can be resource-heavy, so we optimized our validation pipeline to return security verdicts in seconds without compromising detection depth.
  • Handling Evolving Obfuscation: Attackers frequently use URL shorteners and unicode characters to mask malicious links; we implemented normalization checks to unpack and inspect these hidden destinations safely.

What we learned

We gained deep insights into email security protocols (SPF, DKIM, DMARC), modern social engineering tactics, and how to design low-latency AI inference pipelines that deliver instant, actionable security feedback.

Built With

Share this project:

Updates

Submission history