Skip to content

Help & Installation Guides

Installation guides, troubleshooting, and everything you need to get the most from SpoofShield.

Getting StartedOutlook Add-inBrowser ExtensionAlerts & DetectionSettings & ConfigurationBilling & Plans

Installation Video Tutorials

Getting Started

What is SpoofShield?+

SpoofShield is an email security platform that protects you from spoofed senders, phishing attacks, recipient hijacking, and social engineering scams.

It works as an Outlook desktop add-in and as browser extensions for Chrome, Edge, and Firefox — monitoring Gmail, Yahoo Mail, and Outlook.com in real time.

Every email you open is analysed by up to 6 detection engines. If a risk is found, SpoofShield shows a visual alert so you can act before it’s too late.

Which plan do I need?+

Browser Pack ($6.99/user/month) — Chrome, Edge, and Firefox extensions for Gmail and Yahoo Mail. Best for teams who primarily use webmail.

Outlook Guardian ($12.99/user/month) — Full Outlook desktop add-in with org-wide dashboard, admin controls, CSV export, and audit history.

Complete Protection ($14.99/user/month) — Includes both the Outlook add-in and all browser extensions. Best value for organisations that use both.

All plans are billed monthly per user, with no setup fee. You can cancel at any time from your billing page.

Outlook Add-in

How to install the Outlook add-in+

1. Open Outlook desktop and go to Get Add-ins (Home tab → Get Add-ins, or File → Manage Add-ins).

2. Click My Add-ins in the left panel, then scroll to Custom Add-ins at the bottom.

3. Click + Add a custom add-inAdd from URL.

4. Enter the manifest URL: https://app.spoofshield.net/addin/manifest.xml

5. Click OK and restart Outlook.

6. Open any email — the SpoofShield button will appear in the ribbon. Click it to open the task pane.

Tip: Use ‘Add from URL’ (not ‘Add from file’) so the add-in stays up to date automatically.

Installing via Microsoft 365 Admin Center (org-wide)+

For organisation-wide deployment without requiring each user to install manually:

1. Download the manifest: https://app.spoofshield.net/addin/manifest.xml

2. Log in to the Microsoft 365 Admin Center (admin.microsoft.com).

3. Go to Settings → Integrated apps → Upload custom apps.

4. Upload the manifest.xml file and assign it to users or groups.

5. The add-in will appear automatically in Outlook for all assigned users within 24 hours.

The add-in isn’t showing in Outlook+

If the SpoofShield pane doesn’t appear after installation, try the following:

Restart Outlook — the add-in may need a full restart to register.

Remove and re-add — go to My Add-ins, remove SpoofShield, then add it again using ‘Add from URL’.

Check your Outlook version — SpoofShield requires Outlook 2016 or later (Microsoft 365 recommended).

Check COM add-in conflicts — some COM add-ins can block Office.js add-ins. Temporarily disable others and test.

Corporate firewall — ensure app.spoofshield.net is whitelisted. Contact your IT team if needed.

Cached manifest — if you used ‘Add from file’, Outlook caches a local copy. Remove it and re-add via ‘Add from URL’.

Understanding Outlook alerts+

When you open an email, SpoofShield analyses it and shows a risk badge:

Green / Low — No risks detected. The sender appears legitimate.

Amber / Medium — Something looks unusual. Review carefully before replying or clicking links.

Red / High — Significant risk detected. Do not reply, click links, or take any actions until verified.

The task pane shows exactly which detection engines triggered and why, so you can make an informed decision.

Browser Extension

How to install on Chrome or Edge+

1. Open the Chrome Web Store (Chrome) or Edge Add-ons store (Edge).

2. Search for SpoofShield and click the result.

3. Click Add to Chrome or Add to Edge.

4. When prompted, click Add extension to confirm permissions.

5. Open Gmail or Yahoo Mail — SpoofShield activates automatically when you open an email.

You’ll see a SpoofShield badge appear in your browser toolbar confirming it’s active.

How to install on Firefox+

1. Open Firefox and go to addons.mozilla.org.

2. Search for SpoofShield and click the result.

3. Click Add to Firefox and confirm permissions.

4. Open Gmail or Yahoo Mail — the extension activates automatically.

The extension isn’t detecting anything+

If SpoofShield isn’t triggering alerts in Gmail or Yahoo Mail:

Check it’s enabled — click the puzzle piece icon in Chrome/Edge (or the extensions button in Firefox) and make sure SpoofShield is toggled on.

Reload the tab — after enabling the extension, reload your Gmail or Yahoo Mail tab.

Open the full email — alerts only fire when you open an email, not just select it in the list.

Permissions — if you declined permissions during install, go to browser Settings → Extensions → SpoofShield → Permissions and enable site access for mail.google.com and mail.yahoo.com.

Incognito/Private mode — extensions are disabled in private mode by default. Enable it in extension settings if needed.

Which email clients are supported?+

The browser extension currently supports:

Gmail (mail.google.com) — Chrome, Edge, Firefox

Yahoo Mail (mail.yahoo.com) — Chrome, Edge, Firefox

Outlook.com (outlook.live.com) — Chrome, Edge, Firefox

Outlook desktop app is covered by the separate Outlook Add-in (not the browser extension).

Alerts & Detection

What are the 6 detection engines?+

SpoofShield uses up to 6 independent detection engines on every email:

1. Sender domain analysis — checks whether the sending domain matches the claimed organisation’s real domain.

2. Display-name spoofing — detects when a friendly name (e.g. ‘Your Bank’) is used with a completely unrelated email address.

3. Typosquat detection — spots domains that look like real brands but have subtle character swaps (e.g. rn instead of m).

4. VIP impersonation — checks if the email claims to be from a known executive or VIP in your organisation.

5. Billing & financial scam detection — identifies patterns common in invoice fraud, wire transfer scams, and fake payment requests.

6. Tech-support scam detection — flags messages that mimic IT helpdesk or software vendor alerts.

What does the risk score mean?+

Each email receives a risk score from 0–100, calculated from all active detection engines.

0–30 (Low / Green) — No significant signals. The email appears safe.

31–69 (Medium / Amber) — One or more mild signals detected. Read carefully.

70–100 (High / Red) — Strong signals of spoofing or fraud. Treat with extreme caution.

The score is not definitive — treat it as one input alongside your own judgement.

What should I do when I get a high-risk alert?+

When SpoofShield flags an email as high risk:

1. Do not click any links or open attachments.

2. Do not reply or provide any information requested in the email.

3. Verify out-of-band — if the email claims to be from a colleague or vendor, call them directly using a number you already have (not one from the email).

4. Report it — use your email client’s ‘Report Phishing’ or ‘Report Spam’ option.

5. Contact IT/Security — if your organisation has a security team, forward the email to them.

Recipient change alerts (Outlook add-in)+

The Outlook add-in also monitors for recipient address changes within an email thread.

If a reply-to address or CC list changes mid-conversation — a common BEC (Business Email Compromise) tactic — SpoofShield shows a visual flash alert and plays an audio tone.

You can customise the alert colour and sound in the Settings panel of the add-in.

Settings & Configuration

How to customise alert colours and sounds (Outlook add-in)+

In the Outlook task pane, click the Settings tab (gear icon).

You can change:

Alert colour — choose from red, amber, blue, or green for the visual flash effect.

Alert sound — choose between a beep, chime, or silent mode.

Content scam detection — toggle billing/tech-support scam detection on or off.

Settings are saved to your browser’s localStorage and persist across sessions.

Admin configuration (Outlook Guardian & Complete plans)+

Organisation admins can configure SpoofShield centrally from the dashboard.

Admin settings include:

Domain allowlist — whitelist trusted domains so SpoofShield doesn’t flag them.

VIP list — add executive names/emails to the VIP impersonation watch list.

Detection engine toggles — enable or disable specific engines org-wide.

Alert thresholds — adjust the score thresholds for medium and high risk levels.

Changes take effect for all users in your organisation immediately.

How to export alert history+

From the dashboard, click Export CSV in the top right.

This downloads a CSV file containing all alert events for your organisation, including:

• Timestamp, user email, email subject

• Risk level and score

• Which detection engines triggered

Useful for compliance audits and security reviews.

Billing & Plans

How does per-seat billing work?+

Each licensed user counts as one seat. You’re charged per seat per month.

If you have 10 users on Outlook Guardian, your monthly bill is 10 × $12.99 = $129.90.

You can add or remove seats at any time from the billing page.

Adding seats — charged immediately, prorated for the remainder of the billing period.

Removing seats — takes effect at the next renewal date.

How do I upgrade or change my plan?+

Sign in and go to the billing page.

Click Subscribe on the plan you want. You can subscribe to a different plan at any time.

If you want to switch from Browser Pack to Complete Protection, contact support@spoofshield.net and we’ll handle the transition for you.

Is there an annual discount?+

Yes — pay annually and get 2 months free, equivalent to ~17% off.

Annual billing is not yet available directly in the dashboard. Email billing@spoofshield.net with the subject ‘Annual billing enquiry’ to switch.

How do I cancel?+

You can cancel at any time. Your subscription remains active until the end of the current billing period.

To cancel, sign in, go to the billing page, and click Manage subscription, or email billing@spoofshield.net.

There are no cancellation fees or lock-in contracts.

Can’t find what you need?

Sign in to access AI-powered support, or contact our team directly.