All integrations

Setting up the Outlook add-in

The add-in does one thing beside your message: it lists the links inside it, unwraps Microsoft's Safe Links so you see where a link really goes, and opens the one you pick in a throwaway browser in our cloud. This guide covers the install, what it shows, and what it never touches.

The dangerous part of an email is almost never the text. It is the link you are being nudged to click, on a computer that holds your mail, your files and your signed-in sessions. The add-in takes that click somewhere else: the page opens in a disposable browser in our cloud, streamed live to you, and your own machine never loads it.

Nothing else about your mailbox changes. The pane reads the message you have open, in Outlook, and that is the end of it: no account to create, no request sent anywhere, nothing about your email leaving the client. This guide covers the install from its manifest, what the pane lists, how the highlighting in the message body works, and what to do when something looks off.

What it adds to Outlook

  • Every link in the message, in one list. The pane reads the open message and lists the links it contains, from the body and the subject line, de-duplicated and in the order they appear. Microsoft's Safe Links wrapping is removed first, so what you see and what you open is the real destination, not the redirector.
  • The links, highlighted in the email itself. In Outlook clients that support it, the add-in marks the links inside the message body. Click one and a small Guard.ch pane opens with exactly that link in the lead, so you never have to hunt for the right row.
  • The facts a link hides. Each entry shows the host on its own line and notes what you cannot see at a glance: a visible text pointing at a different site than the address behind it, a name in front of the address, a bare IP instead of a domain, a punycode domain that can imitate familiar letters, or plain unencrypted http.
  • A paste box. At the bottom of the pane, any address from anywhere can be pasted and opened the same way.

Install it

The add-in installs from its manifest, a small file that tells Outlook where the pane lives. It works in Outlook on the web, the new Outlook, and classic Outlook, on Microsoft 365 and Outlook.com mailboxes:

  1. Download the manifest: guard.ch/ext/outlook/manifest.xml. Your browser saves a small XML file; that file is the whole install.
  2. Open aka.ms/olksideload. Outlook on the web opens and shows the Add-Ins for Outlook dialog. (In classic Outlook on Windows, the same dialog is behind File › Info › Manage Add-ins.)
  3. Choose My add-ins, scroll to Custom Addins, select Add a custom add-in, then Add from File, and pick the downloaded manifest. Confirm the prompt.
  4. Open any message and choose Guard.ch Companion from the message's apps. The pane opens beside the email, and the add-in follows you into the other Outlook clients on the same mailbox.

Rolling it out to a whole organisation? An administrator deploys the same manifest centrally in the Microsoft 365 admin center under Settings › Integrated apps › Upload custom apps; the upload takes the manifest address directly (guard.ch/ext/outlook/manifest.xml), and assigned users get the pane with no manual step.

What it finds

The pane reads the message the way a careful reader would, and then some. It follows anchors to their real target, picks up addresses written out in the text, sees through the defanged notation security reports use, and ignores the invisible characters that are inserted to break naive matching. Links to Outlook's own surfaces, mail addresses and phone numbers are left out; the rest is listed, with the first 25 shown and the count of everything found stated honestly above the list.

Choosing a link opens the Guard.ch launcher in your normal browser. The page loads in a disposable browser in our cloud with every request, cookie and redirect on the record, streamed live to you, and Outlook never touches the address. The investigation runs in your own Guard.ch account, exactly as if you had pasted the link on the site.

Highlighting inside the message

Beyond the ribbon button, the add-in registers the links in the message body with Outlook itself. Where the client supports it, those links are marked in the message you are reading, and picking one opens a small Guard.ch pane with that link at the top and the rest of the message's links below it.

This is an Outlook feature the add-in asks for, not something it draws: clients too old for it (or configured without it) simply show no highlighting, and the ribbon button with the full list keeps working exactly the same.

What it can and cannot read

The add-in holds Outlook's read-only item permission: it can read the message you have open, and nothing else. It cannot browse your mailbox, cannot send mail, and never receives your mailbox credentials. There is no account and no sign-in in the pane at all.

It also makes no network call: the message is read and the links are found inside Outlook, on your machine. Nothing about the email is sent to us, and the only thing the add-in ever stores is the language you pick in its footer. Guard.ch first sees anything when you choose a link, and what it sees then is that one address.

Works with
Outlook on the web, the new Outlook, and classic Outlook (Microsoft 365 and Outlook.com)
Install
Free; a small manifest added under My add-ins, or deployed centrally
Permissions
Read the open message only (ReadItem)
Sign-in
None: the pane holds no account, no session and no credential
Data sent to Guard.ch
Nothing, until you choose a link; then only that address
Languages
English and German, following your Outlook language

Troubleshooting

The few things that can look wrong, and what they mean:

“Guard.ch could not read this email.” Outlook did not hand the message body over, which happens on some older or restricted clients. The paste box below still works: copy the address you were sent and open it from there.

A link you can see in the email is not in the list. Addresses that are really mail addresses, phone numbers, or Outlook's own surfaces are deliberately left out, and only the first 25 links are shown (the line above the list says how many were found). Anything the list skips can be pasted into the box at the bottom.

Nothing is highlighted in the message body. In-message highlighting needs a recent enough Outlook; older clients skip it silently. The ribbon button opens the pane with the complete list, which is the same result.

The add-in is missing in classic Outlook. Classic Outlook on Windows caches its add-in list and can take up to a day to show a manually added add-in. Outlook on the web and the new Outlook show it immediately; the install itself happens once per mailbox.

The pane is nowhere to be found. The add-in lives on messages you read, not on drafts: open a message, then pick Guard.ch Companion from the message's apps. To remove or re-add it, the same Add-Ins for Outlook dialog holds it under My add-ins, in the Custom Addins section.

Choosing a link asks you to sign in. The investigation runs in your own Guard.ch account, so the launcher meets you with the normal sign-in if the browser it opened in is signed out. Sign in once and the link continues into the investigation.

Other entry points

However a link reaches Guard.ch, it lands in the same capture and the same report. Pair the add-in with the browser extension for everything outside the inbox, or see what an investigation actually captures on the product page.

30 days free, a few clicks away.

Add a card to start, we will not charge it until the trial ends, and cancelling is just a few clicks away.

Start 30-day trial