CheckLink Human Risk Intelligence: Four Free Tools for Better Phishing Decisions
A practical guide to CheckLink's four Human Risk Intelligence tools and the different question each one helps you answer.
Phishing risk is bigger than the link
Many phishing checks begin with a URL, but people often have to make a decision before they know which link matters. A message may look urgent, imitate a manager, use a familiar brand, request a payment, or contain no clickable link at all. Technical signals matter, but so do identity, context, requested actions, confidence, and what happened after the message arrived.
CheckLink's Human Risk Intelligence collection brings those questions into four focused, free tools. The Phishing Message Analyzer helps explain a suspicious message. The Email Identity Checker compares visible and technical identities. The Phishing Resilience Test provides private real-or-phish practice. The Phishing First Aid tool creates an action plan after an interaction.
The tools do not promise certainty, replace a security team, or declare that a message is safe. They are designed to help a person slow down, separate evidence from assumptions, and choose a safer next step.
Tool one: Phishing Message Analyzer
The Phishing Message Analyzer is the best starting point when you have suspicious message text from email, SMS, WhatsApp, Teams, Slack, a marketplace, or social media. It reviews four dimensions separately: source identity, links and domains, manipulation cues, and the action being requested.
That separation is important. Urgent language alone does not prove phishing, and a calm message can still contain a dangerous payment or credential request. The analyzer looks for combinations such as authority plus secrecy, an identity mismatch plus a high-impact action, or an unexpected domain paired with a sign-in request.
Message text stays in the browser. A URL is sent to the existing scanner only when the user explicitly selects that URL for scanning. Read the detailed guide to analyzing suspicious messages for examples and a repeatable review process.
Tool two: Email Identity Checker
Email identity is rarely one field. A message can contain a visible From address, a different Reply-To, a Return-Path used for bounces, a DKIM signing domain, an SPF identity, a Message-ID domain, and links leading somewhere else. Some differences are normal; others need an explanation.
The Email Identity Checker turns pasted headers into a readable identity chain. It compares exact hostnames and registrable domains, highlights alignment and differences, and explains legitimate contexts such as mailing providers, delegated senders, forwarding, and help-desk systems.
It does not cryptographically authenticate pasted headers. Pasted text can be incomplete, reordered, or forged, so the result is a comparison rather than a verified identity claim. The Email Identity Checker guide explains From, Reply-To, Return-Path, SPF, DKIM, DMARC, Message-ID, and linked destinations in plain language.
Tool three: Phishing Resilience Test
Knowing security vocabulary is not the same as making good decisions under pressure. The Phishing Resilience Test uses safe fictional scenarios to practice the moment that matters: deciding whether a message looks legitimate, suspicious, or too uncertain to classify.
Users can choose a six-scenario quick challenge or a full 18-scenario assessment. Each answer includes a confidence rating and immediate feedback about the useful evidence, a signal that may have been missed, and a safer verification action. Results separate false negatives, false positives, and confidence calibration instead of reducing everything to a single dramatic score.
No demographic data is requested or used. Answers stay in the browser tab, and the assessment is educational rather than a scientifically validated measure of a person's security ability. The Phishing Resilience Test guide explains how to use the feedback without turning practice into fear or blame.
Tool four: Phishing First Aid
The question changes after someone clicks, enters a password, shares a verification code, opens a file, sends money, or changes bank details. At that point, another risk score is less useful than a calm, prioritized response plan.
Phishing First Aid covers 12 possible interactions, including work accounts and managed workplace devices. It builds a local checklist across immediate actions, account protection, device protection, payment response, workplace escalation, evidence preservation, reporting, and actions to avoid.
The tool does not contact a bank, employer, platform, authority, or security provider. It cannot repair an account or device. It provides general next-step guidance and repeatedly directs the user to independently opened official services and trusted contact channels. See the complete Phishing First Aid guide for action-specific explanations.
Which tool should you use first?
- You have message text and want to understand the request: use Phishing Message Analyzer.
- You have raw email headers or several conflicting domains: use Email Identity Checker.
- You want private phishing practice and immediate feedback: use Phishing Resilience Test.
- You already clicked, replied, paid, downloaded, or shared information: use Phishing First Aid.
- You only have a URL: start with the [CheckLink scanner](/) or browse all CheckLink tools.
A practical workflow for uncertain messages
- Pause before clicking, replying, downloading, paying, or entering information.
- Use the Message Analyzer to separate identity, pressure, domains, and requested action.
- If raw headers are available, compare the full identity chain in Email Identity Checker.
- Open the claimed service independently instead of using the message link or phone number.
- If an interaction already happened, move immediately to Phishing First Aid.
- Use the Resilience Test later to practice the judgment patterns that were difficult.
Privacy is part of the design
Private content should not become a second source of risk. Message text, pasted headers, scenario answers, confidence ratings, and First Aid selections are processed locally in the browser. They are not placed in the URL, stored as a user history, or sent to an external AI model.
Network activity is deliberate and narrow. The Message Analyzer sends only a URL that the user explicitly chooses to scan. Email Identity Checker sends only a selected domain for a DNS check or a selected URL for scanning. The practice and First Aid tools do not need to transmit the answers that create their results.
Better decisions, not perfect predictions
Human Risk Intelligence is not about scoring people as safe or unsafe. It is about giving people a clearer way to interpret incomplete evidence, notice high-impact requests, acknowledge uncertainty, and verify through a channel the suspicious message does not control.
Start with the tool that matches the immediate question. Use technical evidence where it exists, keep limitations visible, and involve qualified support when accounts, devices, workplace systems, identity data, or money may be at risk.
Continue with the right checker
Phishing Message Analyzer
Understand a suspicious message without uploading it.
Email Identity Checker
Compare visible and technical email identities in one chain.
Phishing Resilience Test
Practice difficult real-or-phish decisions privately.
Phishing First Aid
Get an action plan after a suspicious interaction.
CheckLink browser extension
Open the current page, inspect links from the browser menu, and jump into CheckLink faster without an account.
Works with Chrome and compatible Chromium-based desktop browsers. Firefox and Safari versions are not currently available.

The extension sends a URL only when you choose a scan action. It does not store scan history.