Automatically check suspicious email links for phishing threats

Scans links in your inbox against threat intelligence services and alerts your team when one looks malicious.

How the work actually flows

It branches. Exactly one path is taken; runs once per each link found in emails.

Pattern: Multiple Instances with a priori Design-Time Knowledge (13) · Exclusive Choice (4)

flowchart TD trig(["scheduled or on demand check"]):::trigtime s0["scan inbox for links"]:::svc s1[["check each link against threat services"]]:::mi s2["filter out clean results"]:::task trig --> s0 s0 -->|"one per each link found in emails"| s1 s1 --> s2 gx{"× is link malicious"}:::gate s2 --> gx p00["alert team in slack"]:::task gx -->|"malicious link"| p00 p10["no action taken"]:::task gx -->|"clean link"| p10 p00 --> out p10 --> out out[/"slack alert on malicious links"/]:::out pay{{"catches phishing before an incident"}}:::pay out --> pay classDef task fill:#e7f6fe,stroke:#34b8f0,color:#2c2a29 classDef svc fill:#f6f8fa,stroke:#7c8795,color:#2c2a29 classDef mi fill:#e7f6fe,stroke:#0079a8,color:#2c2a29,stroke-width:2px classDef human fill:#fff,stroke:#0079a8,color:#0079a8 classDef store fill:#f6f8fa,stroke:#0079a8,color:#2c2a29 classDef trig fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigtime fill:#00a4eb,stroke:#0079a8,color:#fff,font-weight:bold classDef trigdata fill:#8ad4f5,stroke:#0079a8,color:#06314c,font-weight:bold classDef gate fill:#fff,stroke:#e8a23d,color:#6b4708,font-weight:bold classDef out fill:#1f9d6b,stroke:#167a53,color:#fff,font-weight:bold classDef pay fill:#06314c,stroke:#021f33,color:#fff
Starts itA stepAn outside serviceRuns once per itemOne path onlyResultPayoff
Build size
Advanced

A larger build with multiple systems, AI reasoning, and custom rules.

Business functions
Messaging & Notifications
Connects
Microsoft OutlookSlackURLScan.ioVirusTotal

The problem it solves

Every day your team gets emails with links that might be phishing attempts, and manually checking each one against threat databases takes time you don't have. A missed malicious link can lead to a real security incident.

Who it fits

An IT or security team responsible for monitoring a shared email inbox for threats.

How it works

  1. The system checks the inbox on a schedule or on demand
  2. It scans each email for links
  3. It checks those links against URLScan.io and VirusTotal
  4. It filters out anything that came back clean
  5. It sends your team a Slack alert with the sender, subject, and threat verdict for anything suspicious
What you get

Phishing links caught before anyone clicks them

Suspicious links in your inbox get checked against threat databases automatically, so your team hears about danger before anyone clicks.

What you get

A Slack alert summarizing which emails contained malicious links and the threat verdict.

What you need

A Microsoft Outlook account, a Slack workspace, and API keys for URLScan.io and VirusTotal.

We can build this. But should you?

The hard question is not how to build it. It is whether this is the right thing to build first.

That is what a Fractional Chief AI Officer figures out with you, before anyone writes a line of code.

Let's Talk Strategy

Related automations

Back to the AI Playbook