Product: Gmail Add-on

Email Security Built Into Your Gmail Inbox.

The CyberCheck360 Gmail add-on runs automatically on every email you open and also checks sender authentication, domain signals, and every link before you act on anything.

Works with Gmail and Google Workspace. Analyses SPF, DKIM, DMARC, sender domain age, and every link automatically.

ISO 27001 Certified
GDPR Ready
Works with Gmail & Google Workspace
Setup in Under a Day

What it checks

What the Add-on Checks On Every Email

Every email you open is automatically analysed. No manual action, no IT configuration, no training required for your team.

Email Header Analysis

  • SPF check (pass / fail / softfail)
  • DKIM signature validation
  • DMARC policy alignment
  • Return-path vs sender domain comparison
  • Sender domain age and newly registered domains flagged
  • Reply to mismatch detection

Link Scanning

  • Every URL in the email body checked against live threat intelligence
  • Domain reputation and category lookup
  • Malicious links flagged inline and visible without clicking
  • Shortened URL expansion and analysis

Sandbox Access

  • Click "Open in Sandbox" on any link to view it in an isolated cloud browser
  • Full screenshot of where the link leads without visiting it on your device
  • Free users: 3 sandbox sessions per day
  • Paid users: unlimited sandbox with file scanning and full session recording

Who it's for

Built for Teams That Can't Afford a Breach

You don't need a dedicated security team to be protected. CyberCheck360 works for any team running Gmail or Google Workspace.

Google Workspace Admins at 25-500 Person Companies

Get full org wide visibility of every link clicked across your organisation without adding headcount. The admin dashboard shows everything. Setup takes hours, not weeks.

Finance Teams Handling Supplier Payments

Attackers target finance teams with fake invoices and spoofed supplier emails. Sender domain age checks and return path analysis catch these before your team acts on them.

Legal Teams With High-Value Client Communications

Law firms and professional services handle millions in client funds via email. One spoofed conveyancing email can be career ending. Every sender is verified automatically.

Healthcare Organisations With GDPR Obligations

A phishing breach in healthcare isn't just an IT incident it's a patient data violation with ICO consequences. CyberCheck360 provides the audit trail regulators expect to see.

How it works

Three Steps to a Protected Inbox

No email routing changes. No DNS record updates. No admin permissions required for individual users.

01

Open Any Email in Gmail

The add-on sidebar appears automatically on the right side of your inbox. No action required analysis starts immediately when you open a message.

02

See the Full Security Analysis

Authentication results, sender domain age, link verdicts are all visible at a glance without any manual action. Green means safe. Anything else tells you why.

03

Act with Confidence or Report With One Click

Flag suspicious emails, open links in sandbox, or report the message directly from the sidebar. No need to raise an IT ticket. No waiting for someone else to act.

Pricing

Free to Start. More When You Need It.

Install for free from Google Workspace Marketplace. Upgrade when your team needs admin visibility, unlimited sandboxing, and organisation-wide controls.

FAQ

Frequently Asked Questions

Everything you need to know before installing. Not here? Talk to us.

CyberCheck360 is built specifically for phishing interception at the link level. It analyses every link inside every email in real time, checking sender authentication, domain age, and link reputation, and opens suspicious URLs in a cloud sandbox before they reach your device. It installs in minutes from the Google Workspace Marketplace with no IT configuration required.

The CyberCheck360 add-on detects phishing automatically when you open any email. It checks SPF, DKIM, and DMARC authentication to verify the email came from where it claims. It also checks the sender domain age, analyses the return-path for mismatches, and scans every link against live threat intelligence. Results appear in the Gmail sidebar without you doing anything manually.

It is a plugin installed directly into Gmail that analyses incoming emails for phishing signals, authentication failures, and malicious links without you leaving your inbox. CyberCheck360 appears as a sidebar panel every time you open an email, showing authentication results and link verdicts before you act on anything.

These are email authentication protocols that verify whether an email was sent from a legitimate server. SPF checks if the sending server is authorised by the domain owner. DKIM verifies the email has not been tampered with in transit. DMARC combines both and tells receiving servers what to do when checks fail. When any of these fail, it is a strong signal the email may be spoofed or impersonated. CyberCheck360 checks all three automatically on every email you open.

Attackers frequently register brand new domains to send phishing emails because new domains have not yet built a bad reputation and can pass basic filters. A domain less than 30 days old sending business email is a strong phishing signal. CyberCheck360 surfaces this in the sidebar immediately so you can make an informed decision before clicking anything.

The Gmail add-on analyses emails before you act on them, checking authentication headers and link reputation while you read your inbox. The browser extension protects you at the point of click, intercepting every URL you visit across any site in any tab. They cover different attack surfaces. If someone forwards a phishing link to a personal email and you click it in your browser, the add-on will not catch that but the browser extension will. We recommend running both for complete coverage.

A sandboxed browser is an isolated cloud environment where you can open a link and see what it does without it running on your device or network. If the destination is malicious, the damage stays entirely contained in the sandbox. CyberCheck360's sandbox also captures screenshots and, for paid users, full session recordings so you can see exactly what a suspicious link does before deciding whether to proceed.

Yes. CyberCheck360 is free to install from the Google Workspace Marketplace. Free users get full SPF, DKIM, DMARC, sender domain age, and link reputation analysis on every email plus 3 sandbox sessions per day. Paid plans add unlimited sandboxing, file scanning, admin dashboards, audit trails, and org-wide controls.

Yes. The add-on works fully with Google Workspace including Business Starter, Standard, Plus, and Enterprise tiers. It also works with personal Gmail accounts. It installs from the Google Workspace Marketplace and appears as a sidebar panel inside Gmail on both web and mobile.

No. The add-on installs directly from the Google Workspace Marketplace and works immediately. There are no email routing changes, no DNS record updates, and no admin permissions required for individual users. Paid plan customers who want org-wide admin dashboards and controls will need standard Google Workspace admin access to deploy across the organisation.

During normal analysis, CyberCheck360 never reads, stores, or processes the body content of your emails. Only the links inside the email and metadata such as the sender address, return-path, and authentication headers are sent to our servers for analysis. Your email body stays entirely on your device. The only exception is when you choose to report an email for further analysis. That is a deliberate action you take, and you will be clearly informed before anything is submitted. Nothing is ever sent without your explicit instruction.

During normal analysis, only URLs and email metadata are sent to our servers. The email body, subject line, and any personally identifiable content never leave your device. SPF, DKIM, and DMARC records are public by design so checking them involves no private data at all. If you choose to report an email for further analysis, you will be prompted before any content is submitted. That action is always your choice, never automatic.

It works with both. CyberCheck360 supports personal Gmail accounts as well as paid Google Workspace tiers. Whether you are using Gmail for personal email or running a business on Google Workspace, the add-on installs and works the same way. Some admin and org-wide features on paid plans require a Google Workspace account with admin access.

No. CyberCheck360 operates as a read-only sidebar panel and does not interact with your Gmail filters, labels, routing rules, or spam settings in any way. It does not move, delete, or modify emails. Everything you have set up in Gmail stays exactly as it is. The add-on simply adds a security analysis layer on top of what you already have.

Analysis runs automatically when the add-on sidebar is open and you open an email. If the sidebar is closed, the add-on is not actively running on that message. To make sure every email gets analysed without any manual steps, keep the CyberCheck360 panel pinned in your Gmail sidebar. This way analysis happens automatically every time you click on a message.

Pin the CyberCheck360 add-on in your Gmail sidebar. Once pinned, the panel stays open permanently so every email you click is analysed automatically without any extra steps. To pin it, open Gmail, click the CyberCheck360 icon in the right sidebar, and select the option to keep it open. The add-on will then be active by default for every email you read going forward.

Learn How Email Authentication Works

Understand the protocols that protect your email and why they're not enough on their own.

More Ways to Stay Protected

Pair the Gmail add-on with our browser extension and Outlook add-on for protection wherever you work.