Help & support
Installing the add-in
- Download manifest.xml with the button above and save it anywhere you'll find it.
- In Outlook, open Get Add-ins — on the Home ribbon, or under the three-dots menu when a message is open.
- Choose My add-ins → Add a custom add-in → Add from file, and pick the file.
- Restart Outlook, open any email, and click the LureSight button.
Don't see the option? Some workplaces switch off custom add-ins. Send the manifest file to your IT helpdesk and ask them to “deploy this Outlook add-in” — that phrase tells them exactly what to do.
Button greyed out? “Get Add-ins” only lights up for Microsoft-hosted mailboxes (Microsoft 365 or outlook.com) — and it follows the account you have selected. iCloud, Gmail-via-IMAP, and POP accounts can't run Outlook add-ins at all; that's Outlook's platform, not LureSight. Click a message in a Microsoft mailbox first and try again, or add a free outlook.com account to test with — the aka.ms/olksideload shortcut opens the add-ins dialog in Outlook on the web for whichever account is signed in. And if your mail lives on iCloud or Gmail, the web scanner was built exactly for you — same engine, nothing to install. Or skip the browser entirely: forward the suspicious message to scan@in.luresight.com and the analysis comes back by email.
For IT administrators
Two kinds of updates — only one ever needs you. The add-in is a hosted web app: its code and detection engine load from luresight.com each time the pane opens, so those updates reach users automatically. Only a manifest change (new buttons or capabilities — rare) needs a redeployment.
To deploy or update centrally (requires a Global admin or Exchange admin role):
- Download manifest.xml (save as a file).
- In admin.microsoft.com, open Settings → Integrated apps. Deployments made through the older interface appear under the Add-ins link on that page.
- First deployment: Upload custom apps → select the manifest file → choose the users or groups. Update: select LureSight → Update app (or Update add-in in the older list) → upload the same file. The existing user assignment is kept.
- Confirm the listed version matches the manifest, and allow up to 24 hours to propagate; users pick it up when Outlook next starts.
What you're approving: LureSight requests read-only access to the open message (“ReadItem”) and nothing else. Scanning runs on the user's device; nothing is sent anywhere unless the user explicitly reports or shares a message — the Privacy Policy has the full detail.
Forwarding as an attachment (the fullest scan by email)
Anything forwarded to scan@in.luresight.com gets scanned — but how you forward it matters. A normal (inline) forward rewrites the message and throws away its original delivery headers, so sender authentication (SPF/DKIM/DMARC) can't be checked and the reply will say the scan was partial. Forward as an attachment and the original message travels intact — headers and all.
Apple Mail (Mac): click the message once, then choose Message → Forward as Attachment from the menu bar, and send it to scan@in.luresight.com. On iPhone and iPad, Mail can't forward as an attachment — forward from a Mac, or screenshot the message and scan the picture at the web scanner.
Outlook (new Outlook & Outlook on the web): open the message, click the … (More actions) menu → Forward → Forward as attachment. In classic Outlook for Windows, select the message and press Ctrl+Alt+F.
Gmail (on the web): open the message, click the ⋮ (More) menu → Forward as attachment — or right-click the message in the inbox list and pick it there. The Gmail phone app can't; use gmail.com in a browser.
Reading the result
The dial scores the message from 0 to 100. Findings are highlighted in a copy of the message, each with a plain-English reason. Colour marks severity: red is a strong signal, amber is worth a look, green is informational. The ? button inside the panel explains the scoring in more detail.
A high score is not proof of phishing, and a low score is not a guarantee of safety. LureSight is an assistant — when something feels wrong, trust that instinct and verify through a channel you already know.
If a verdict looks wrong
Both directions are useful to know about: a safe message scored high, or a phishing message scored low. Email support@luresight.com with what you saw. Please don't forward the original message — a description of the pattern is enough, and it keeps your mail private.
Common problems
- The button doesn't appear. Restart Outlook completely; add-ins are only picked up on start.
- “Couldn't reach the community service.” The scan still works — only the shared-model part needs the network. Try again later.
- Nothing happens on an encrypted or protected message. Expected: LureSight can only read what Outlook makes available to add-ins.
- “Outlook's add-in runtime didn't start.” A known issue in the new Outlook for Mac, whose add-in host doesn't finish starting sideloaded panes — not specific to LureSight. Use Outlook on the web with the same account (the add-in is already there) or classic Outlook; Windows is unaffected. Updating Outlook may resolve it.
Privacy
Scanning happens on your device. Nothing is sent anywhere unless you explicitly choose to share — Submit to community in the add-in, or Share this result in the web scanner — and then it is scrubbed of personal details first. The Privacy Policy has the full detail.
Contact
LureSight is run by LureSight LLC. For support: support@luresight.com. For privacy and legal requests: legal@luresight.com.
← Back to LureSight