Don’t pay
A lookalike address, a new bank account, or a signature that no longer matches.
One button writes to the address you already have for them, not the one the email came from.
Fromensics checks the Gmail or Outlook email you open and gives you one answer: Don’t pay, Check first, or Nothing looks off. It works on your device. The email never leaves your browser.
A live example with made-up emails. In Chrome, this runs next to your mail.
What you get
Invoice fraud works by changing one detail in an email that looks like it came from someone you trust. Every report starts with what to do about it. The evidence is one tap away.
A lookalike address, a new bank account, or a signature that no longer matches.
One button writes to the address you already have for them, not the one the email came from.
Something needs a second look, like a brand-new domain or a link that goes somewhere other than it says.
Check once, or let Fromensics always check. Only the domain is sent.
No warning signs were found. Calm when nothing is wrong, loud only when something is.
Add the sender to your trusted senders. We never call an email “safe”.
How we know
Authentication, domain alignment, lookalikes, payment details, threat-feed matches, and signatures are all checked in code. The same email always gets the same answer.
4 reasons this looks wrong. 11 things checked on this device.
Who sent it
What it asks
What we checked
Ask about this email
Tap a suggestion or type a question. Chrome’s built-in AI (Gemini Nano) answers from the evidence Fromensics found, right here in your browser.
Gemini Nano in Chrome · on this device
Privacy by architecture
By default, nothing leaves your browser. When a lookup would change the answer, Fromensics asks first, sends one indicator, and shows you exactly what it sent.
Your browser
Partnership intro — Brightline Media
jordan@bl-partnerships.co
Subject, body, and recipients stay here
Domain registry
Public records for one domain. It never sees who you are talking to.
Checked on this device · nothing was sent
The subject, body, recipients, and links are read in your browser. We don’t use the Gmail API or Microsoft Graph, and we never ask for account access.
Choose Check once, or turn on automatic checks. One domain or link host is sent, never the message, and every lookup is listed in the report.
No sign-up. We don’t run a central database of emails, keys, or contacts. You can erase your history, trusted senders, and keys in Settings.
Signed email
A hijacked mailbox can send a perfect-looking invoice. It can’t sign one with a key it doesn’t have. When your contacts sign with Fromensics, you know who sent it and that the payment details weren’t changed on the way.
Invoice 1048 — September
Signed with the key you confirmed by phone on 12 March. Nothing in it changed after it was signed.
Sterling Cooper signed this email, but the bank account in it isn’t the one they signed.
Call Sterling CooperWhat they signed
Fromensics makes an Ed25519 key in this browser. It can’t be exported, it’s never synced, and it’s never sent to us. Your emails get a short footer that covers the sender, recipients, subject, links, bank details, and amounts.
The first time a contact’s key appears, call them on a number you already have and compare four words.
Northstar is now trusted. Their signed emails will show as verified. If their key ever changes, you’ll be asked again.
Then it isn’t their key. Don’t trust it, and keep using the number you already have for them.
People without Fromensics can check a signature at fromensics.com/s. The signature stays in the part of the link that’s never sent to our server.
Check a signatureSigning proves who sent an email. It doesn’t encrypt it.
How it works
Fromensics checks one email at a time, when you ask. It doesn’t scan your inbox.
Any message in Gmail or Outlook on the web. Nothing is read until you ask.
It sits right under the sender and shows the answer there. Or press AltShiftF.
The side panel shows what to do, why, and one button to do it. How we know is one tap away.
Got a suspicious link or text somewhere else? Select it, right-click, and choose Check with Fromensics.
New in 0.1.7
Every report gives one answer, with one reason and one next step.
In Gmail and Outlook, the answer shows right there, next to who sent it.
Tap a suggestion or type a question. Chrome’s built-in AI answers on this device.
You decide when a check goes online. Only the domain is sent, and the report shows it.
New signing keys are confirmed with four words, and the signature footer is quieter.
Check selected text or a link from the menu, or press Alt+Shift+F for the open email.
Pricing
Checking emails, signed email, and trusted senders are free, with no account. Pro adds deeper online checks through our privacy proxy.
$0
No account, no card
$5.99/month
Cancel anytime on Whop
Opens Whop. After you buy, paste the license key in the extension Settings.
Either way, the email stays on your device. Online checks send one indicator (a domain, link host, or, for Pro web search, a company or person name), never the message. Fromensics Lite is the free listing on Whop.
Yes, in Outlook on the web: outlook.live.com, outlook.office.com, outlook.office365.com, and outlook.cloud.microsoft. It doesn’t run in the Outlook desktop app, because desktop apps can’t run Chrome extensions.
No. The subject, body, and recipients are checked in your browser. An online check happens only when you choose Check once or turn on automatic checks, and it sends one indicator, like a domain, never the message. Every lookup is listed in the report. Details are in the privacy promise.
No. Rules in code decide it. Chrome’s on-device AI (Gemini Nano) explains the evidence and answers your questions, but it can’t change the answer, and an explanation that contradicts it is dropped. If the AI isn’t available on your computer, every check still runs.
Yes. Checking emails, signed email, and trusted senders are free, with no account. Fromensics Pro is optional, $5.99 a month, sold by Fromensics on Whop. It adds deeper online checks through our privacy proxy.
The email you opened: the sender’s name and address, the subject and date, the body and links, and attachment names if the page shows them. It reads it after you tap Check sender. If you turn on trust badges, it also reads the visible sender addresses in your Gmail inbox list, and nothing else.
Anyone can make a key that claims an address. The four words are a short fingerprint of the real key. Comparing them on a call you start proves the key belongs to the person you know. After that, their signed emails show as verified.
No. Signing proves who sent the email and that the payment details didn’t change. It doesn’t hide what the email says.
Free, no account, and the email never leaves your browser.