Skip to scanner
FileScan

FileScan

Help

01

About FileScan

FileScan is a free online service that scans uploaded files for viruses and malware using the ClamAV antivirus engine.

02

How to use

1. Drag & drop a file, click to browse, or paste with ⌘/Ctrl + V. 2. Upload and scanning start automatically. 3. See the verdict — green for clean files, red when a threat is detected. 4. Use the SHA-256 hash to get a second opinion on VirusTotal.

03

Checking emails for phishing

Save an email as an .eml file and upload it to check it against known phishing emails and for spoofed links (where the URL shown differs from the real destination). [How to save as .eml] • Gmail: open the email, click "⋮" → "Download message" • Outlook (web / new Outlook): open the email, click "…" (More actions) → "Save as" or "Download" • Apple Mail (Mac): File → Save As → choose "Raw Message Source" as the format • Thunderbird: File → Save As → File Classic Outlook for Windows saves .msg files, and phone mail apps can't save .eml, so save the email from a web or desktop mail client instead. Spoofed links impersonating major brands (Amazon, Rakuten, major banks, card issuers, carriers, delivery companies and more) are detected, but text-only links like "Log in here" and QR-code tricks can't be detected.

04

About ClamAV

ClamAV is an open-source antivirus engine capable of detecting trojans, viruses, malware, and other threats. The virus definition database is updated regularly.

05

Privacy

Uploaded files are processed in memory only and discarded once the scan completes. File contents are never shared with third parties. The SHA-256 hash is calculated inside your browser.

06

Limitations

The maximum file upload size is 10MB. All file formats are supported, but 100% detection is not guaranteed. For critical files, we recommend verifying with multiple security tools.

Detection name

Heuristics.Phishing.Email.SpoofedDomain

Suspected phishing

Risk
Medium
Verdict
Phishing

Name breakdown

  1. HeuristicsPrefix
  2. PhishingDetail
  3. EmailDetail
  4. SpoofedDomainDetail

Overview

Typical phishing traits were found in an email or HTML file — for example, a link whose visible text points somewhere other than its real destination (e.g. Heuristics.Phishing.Email.SpoofedDomain).

What to do if it's detected

  1. 01Don't click links or enter any information.
  2. 02Open services directly from your bookmarks or the official app.
  3. 03If you already entered details, change your password immediately — and contact your card issuer if you entered card information.

Could it be a false positive?

Click-tracking links from email marketing services can trigger it on legitimate emails.

Check your own files

Drop a file into FileScan to scan it with ClamAV. No sign-up, and your file is never stored.

Scan a file →