See Fish Catcher in action

This page is safe, and Fish Catcher shows green here. Below is what it looks like when a page is not.

Live demo

Check it right now

If Fish Catcher is installed, the toolbar fish is green on this page. Click it: the panel says No suspicious signs found for fishcatcher.dev. That quiet green is what you will see on almost every page you visit. Not installed yet? Install it first, then come back.

Green: No suspicious signs found
fishcatcher.dev (this page)

What it looks like when a page is not safe

These are faithful mock-ups of the panel on real kinds of phishing addresses, with the exact wording the extension uses. The addresses are examples, not links.

Yellow: Some unusual signs. Double-check the address
account-verify-check.top
  • Contains a word often used in phishing pages (verify)
  • Uses a high-abuse domain ending (.top)
Orange: Multiple phishing indicators. Be careful before logging in
secure-login-update.info
  • Contains a word often used in phishing pages (login)
  • The page asks for a password on a site that isn't a known legitimate domain
Red: Strong phishing signs. Don't enter passwords here
paypa1-account.com
  • Domain looks like a misspelling of paypal.com
  • The page asks for a password on a site that isn't a known legitimate domain

On red and orange pages the panel also offers one safe action: an Open paypal.com button that takes you to the brand's genuine site instead. And if you start typing a password on such a page, a warning banner slides in at that exact moment, whatever your settings. It warns; it never blocks.

Why this page is green, not a staged warning

fishcatcher.dev is on the extension's list of known legitimate domains, and Fish Catcher never raises an alarm on a page that has not earned one, not even ours. A demo that faked a red warning on a safe page would be exactly the kind of trick the extension exists to catch. So the live part of this demo is the quiet green verdict above, and the warnings are shown as honest mock-ups.

Want proof it stays quiet in general? The benchmark page publishes the false-positive rate over the 100,000 most-visited sites and the catch rate over live phishing feeds, with the run dates.