Free tools and reference material for spotting risk early.
Test yourself, check a suspicious email, or report one — no account or waitlist signup required for the tools below.
Tools you can use right now.
Built to be genuinely useful, not just a lead form in disguise.
Phishing Awareness Quiz
Six realistic scenarios. See how many you'd catch before they landed in your inbox.
Take the quiz → LIVEEmail Analyzer
Upload a suspicious .eml/.msg file or paste headers — Trawl checks sender authenticity, SPF/DKIM/DMARC, and links.
Analyze headers → LAUNCHING WITH TRAWLEmail Spoofing Test
Send a controlled spoof test to your own domain to see if it lands in the inbox. Needs live sending infrastructure, so this ships with Trawl access.
See Trawl → LIVEReport a Phishing Email
Describe or paste a suspicious email and get guidance on what to do next.
Report an email →Guides.
Short, practical reads — no signup required.
How to spot a phishing email in under 10 seconds+
Most phishing emails share a handful of tells: a sender domain that's close to, but not exactly, the real one; urgency language ("act within 24 hours" or "your account will be suspended"); a generic greeting instead of your name; and a link that, when you hover over it, doesn't match the text or the organization it claims to be from.
The fastest check is the sender's actual email address, not just the display name — display names are trivial to fake. If anything asks you to act immediately or bypass a normal process, slow down and verify through a channel you already trust, like calling a known number rather than one in the email.
What OSINT can reveal about your organization+
Open-source intelligence pulls together everything about your organization that's already publicly discoverable — employee names and roles from social media, exposed subdomains and infrastructure, leaked credentials from past breaches, and metadata buried in public documents.
None of it requires breaking in anywhere. That's exactly why it matters: an attacker doing reconnaissance before a targeted phishing campaign or social engineering attempt is running the same searches. Knowing what's exposed is the first step to reducing it.
VAPT vs. a vulnerability scan — they're not the same thing+
A vulnerability scan is automated: a tool checks your systems against a database of known issues and produces a list. It's fast and useful, but it doesn't tell you whether those issues are actually exploitable in your specific environment, or what an attacker could do once inside.
Penetration testing adds a human element — someone actively trying to chain smaller weaknesses together the way a real attacker would, to see how far they can actually get. Most mature security programs use both: scanning for continuous coverage, testing for real-world validation.
Building a security awareness program people don't tune out+
Annual training modules tend to fail for a simple reason: they're disconnected from what people actually experience day to day. By the time a real phishing email arrives, the training is a distant memory.
Programs that stick tend to share three traits: they're continuous rather than annual, they use real (simulated) scenarios instead of abstract slides, and they respond to behavior — someone who clicks a simulated phish gets short, targeted follow-up training, not the same generic course as everyone else.
Glossary.
Plain-language definitions for terms used across our services.
- OSINT
- Open-Source Intelligence — information gathered from publicly available sources rather than hacking or insider access.
- Due Diligence
- The process of verifying facts about a person, vendor, or organization before entering into a deal, hire, or partnership.
- VAPT
- Vulnerability Assessment & Penetration Testing — combined automated scanning and manual testing to find exploitable weaknesses.
- Penetration Testing
- Authorized, simulated attacks on a system to find and demonstrate real-world exploitable vulnerabilities.
- Social Engineering
- Manipulating a person, rather than a system, into taking an action that compromises security — like clicking a link or sharing a password.
- Pretexting
- Creating a fabricated scenario or identity to trick someone into giving up information or access.
- Phishing
- Fraudulent messages, usually email, designed to trick someone into revealing credentials or installing malware.
- Spear Phishing
- A phishing attempt targeted at a specific person or organization, using details that make it more convincing than a generic attempt.
- SPF
- Sender Policy Framework — a DNS record listing which mail servers are allowed to send email for a domain.
- DKIM
- DomainKeys Identified Mail — a cryptographic signature added to outgoing email that lets receivers verify it wasn't altered in transit.
- DMARC
- A policy that tells receiving mail servers what to do when a message fails SPF or DKIM checks — and reports on it.
- Attack Surface
- Every point — technical or human — where an unauthorized user could try to gain access to a system or organization.
- Threat Actor
- An individual or group responsible for, or capable of, carrying out an attack against a system or organization.
- Red Team / Blue Team
- Red team simulates attackers; blue team defends. Testing both sides sharpens real-world readiness.
- Zero-Day
- A vulnerability that's exploited before the vendor has released a fix — meaning there's "zero days" of protection.
- MFA
- Multi-Factor Authentication — requiring more than one form of verification (like a password plus a code) to log in.
- Human Risk Assessment
- An evaluation of how susceptible an organization's people are to manipulation, social engineering, or process failure.
- Business Email Compromise (BEC)
- An attack where a threat actor impersonates a trusted contact, often an executive, to trick someone into a wire transfer or data leak.
Articles.
We're building out longer-form content — check back soon.