Help & support

Up and running in two minutes.

Install the add-in · read a result · report a wrong verdict

Help & support

Getting LureSight working, and what to do when something looks wrong.

Installing the add-in

⬇︎  Download manifest.xml One small file — the whole install is this download plus four clicks.
  1. Download manifest.xml with the button above and save it anywhere you'll find it.
  2. In Outlook, open Get Add-ins — on the Home ribbon, or under the three-dots menu when a message is open.
  3. Choose My add-ins → Add a custom add-in → Add from file, and pick the file.
  4. Restart Outlook, open any email, and click the LureSight button.

Don't see the option? Some workplaces switch off custom add-ins. Send the manifest file to your IT helpdesk and ask them to “deploy this Outlook add-in” — that phrase tells them exactly what to do.

Button greyed out? “Get Add-ins” only lights up for Microsoft-hosted mailboxes (Microsoft 365 or outlook.com) — and it follows the account you have selected. iCloud, Gmail-via-IMAP, and POP accounts can't run Outlook add-ins at all; that's Outlook's platform, not LureSight. Click a message in a Microsoft mailbox first and try again, or add a free outlook.com account to test with — the aka.ms/olksideload shortcut opens the add-ins dialog in Outlook on the web for whichever account is signed in. And if your mail lives on iCloud or Gmail, the web scanner was built exactly for you — same engine, nothing to install. Or skip the browser entirely: forward the suspicious message to scan@in.luresight.com and the analysis comes back by email.

For IT administrators

Two kinds of updates — only one ever needs you. The add-in is a hosted web app: its code and detection engine load from luresight.com each time the pane opens, so those updates reach users automatically. Only a manifest change (new buttons or capabilities — rare) needs a redeployment.

To deploy or update centrally (requires a Global admin or Exchange admin role):

  1. Download manifest.xml (save as a file).
  2. In admin.microsoft.com, open Settings → Integrated apps. Deployments made through the older interface appear under the Add-ins link on that page.
  3. First deployment: Upload custom apps → select the manifest file → choose the users or groups. Update: select LureSight → Update app (or Update add-in in the older list) → upload the same file. The existing user assignment is kept.
  4. Confirm the listed version matches the manifest, and allow up to 24 hours to propagate; users pick it up when Outlook next starts.

What you're approving: LureSight requests read-only access to the open message (“ReadItem”) and nothing else. Scanning runs on the user's device; nothing is sent anywhere unless the user explicitly reports or shares a message — the Privacy Policy has the full detail.

Forwarding as an attachment (the fullest scan by email)

Anything forwarded to scan@in.luresight.com gets scanned — but how you forward it matters. A normal (inline) forward rewrites the message and throws away its original delivery headers, so sender authentication (SPF/DKIM/DMARC) can't be checked and the reply will say the scan was partial. Forward as an attachment and the original message travels intact — headers and all.

Apple Mail (Mac): click the message once, then choose Message → Forward as Attachment from the menu bar, and send it to scan@in.luresight.com. On iPhone and iPad, Mail can't forward as an attachment — forward from a Mac, or screenshot the message and scan the picture at the web scanner.

Outlook (new Outlook & Outlook on the web): open the message, click the … (More actions) menu → Forward → Forward as attachment. In classic Outlook for Windows, select the message and press Ctrl+Alt+F.

Gmail (on the web): open the message, click the ⋮ (More) menu → Forward as attachment — or right-click the message in the inbox list and pick it there. The Gmail phone app can't; use gmail.com in a browser.

Reading the result

The dial scores the message from 0 to 100. Findings are highlighted in a copy of the message, each with a plain-English reason. Colour marks severity: red is a strong signal, amber is worth a look, green is informational. The ? button inside the panel explains the scoring in more detail.

A high score is not proof of phishing, and a low score is not a guarantee of safety. LureSight is an assistant — when something feels wrong, trust that instinct and verify through a channel you already know.

If a verdict looks wrong

Both directions are useful to know about: a safe message scored high, or a phishing message scored low. Email support@luresight.com with what you saw. Please don't forward the original message — a description of the pattern is enough, and it keeps your mail private.

Common problems

Privacy

Scanning happens on your device. Nothing is sent anywhere unless you explicitly choose to share — Submit to community in the add-in, or Share this result in the web scanner — and then it is scrubbed of personal details first. The Privacy Policy has the full detail.

Contact

LureSight is run by LureSight LLC. For support: support@luresight.com. For privacy and legal requests: legal@luresight.com.

← Back to LureSight