Return Path
Runs offline What it catches Privacy Limits

AI writes a flawless email. It still can't forge the envelope.

idle
Drop the .eml file
Try a specimen
Gmail (web)
Open the message → ⋮ menu → Show original → Copy to clipboard.
Outlook (web)
Open the message → ⋯ menu → View → View message source.
Outlook (desktop)
Open the message → File → Properties → copy the Internet headers box.
Apple Mail
View → Message → Raw Source (⌥⌘U).
Thunderbird
View → Message Source (Ctrl+U).
Any client
Drag the message to your desktop to save a .eml, then drop it above.

Headers alone are enough for the sender analysis. Include the body too and you also get the link and attachment analysis.

An answer, and the reason for it.

Not a score out of ten. A verdict, what to do about it, and every separate thing that is wrong with the message.

The report: a Forged verdict with five critical findings, advice on what to do, and the sender panel showing the From address marked as impersonation while the Return-Path belongs to a different domain.

Anatomy of a message

Everything an email is really carrying.

the part you are shown FROM PayPal Service RETURN-PATH mailer-7f2a.top LINKS 3 — one hides its target ATTACHED Invoice.pdf.js
  1. 01

    Who it says it is from

    A name anyone can type. Nothing anywhere checks it.

  2. 02

    Who actually sent it

    The address the computers used. Usually a completely different company, and never shown to you.

  3. 03

    Where the links really go

    The words in a link are just words. Every one is opened up and compared against its true destination.

  4. 04

    What came attached

    Windows hides the real file type, so a program can arrive looking exactly like a PDF.

Open any point and it shows you the proof.

Each line is something the message actually did, written out in plain words, with the exact text from the email underneath it.

The evidence list with three findings opened, each explaining a problem in plain language and quoting the header it came from.

What it looks for

Six ways an email lies about
who sent it.

Not one of them is a spelling mistake. All of them are sitting in the message already, and each is something a genuine email almost never does.

PayPal Service Account suspended alerts@paypa1.com hidden on phones

A fake name on the envelope

The sender name is just text — anyone can type anything there, and nothing checks it. Phones show you that name and hide the real address completely.

paypal.com THE REAL ONE paypa1.com A DIGIT, NOT AN L

A name that isn't quite the name

A one swapped for an l. A letter from another alphabet that looks identical. Reading carefully does not help — so it is checked character by character instead.

10:12 10:14 10:09 TIME RUNS BACKWARDS

A journey that can't have happened

Every computer that passes the message along stamps the time. Read in order they are a travel history — and invented stops tend to arrive before they left.

Sender checks out Signature valid Domain agrees STILL A SCAM

Sometimes everything checks out and it is still a scam.

If someone steals a real person's email account, the message really does come from them. Every automatic check passes, because nothing is fake except the person typing.

This is the case that beats every tool like this one, so rather than bury it, it is one of the built-in examples: all three checks green, the verdict still Suspicious, because the reply would go to a stranger and the message leans on urgency and secrecy. It is also why the answer is never the word "safe".

Invoice.pdf .js

A file that isn't what it says

Windows hides the real file type, so a program can arrive looking exactly like a PDF. The bit that runs is the bit you were not shown.

your school a stranger YOUR REPLY GOES HERE

A reply that goes to someone else

The message looks like it came from your boss. Hit reply and it quietly goes somewhere else. That one swap is behind most invoice and gift-card scams.

[ how it works ]

Three steps, no account, nothing uploaded

About thirty fixed rules, run on your own machine. No artificial intelligence, no score out of ten, no guessing — and every answer shows you the line it came from.

  1. Reply Show original

    step 01

    Copy the email's hidden details

    In Gmail it is called Show original; in Outlook, View message source. It looks like gibberish. That is fine — paste the whole lot in.

  2. CHECKED ON YOUR DEVICE

    step 02

    It reads what the computers wrote

    Who really sent it, where its links go, what is attached and the route it travelled. It takes about a thousandth of a second, and nothing leaves your browser.

  3. Forged WHY?

    step 03

    You get a reason, not a score

    Open any point and it shows you the exact line in the email that proves it. That is the difference between trusting a tool and being able to check it.

Privacy

Nothing you paste ever leaves
this browser tab.

This page loads a dozen local files and then makes no further network requests. Not analytics, not fonts, not a scanning API. You can disconnect from the internet and it will keep working — which is a claim you can check in your own developer tools rather than take on trust.

That matters because every comparable tool asks you to paste your email into someone else's server. Reporting a phishing attempt shouldn't require handing a stranger the contents of your inbox.

0network requests after load
0accounts, cookies or storage
0dependencies or build steps

The cost, stated plainly: DKIM signatures can't be re-verified here, because that needs a DNS lookup for the sender's public key. Return Path reads the result your mail provider already recorded.

Limits

What this can't do.

A tool that only tells you what it caught is half a tool. Here's where this one stops.

See where a link really goes before you tap it.

The message is rebuilt as plain text, so nothing in it can run. Every link becomes a button that tells you its true destination.

The annotated message: a link reading paypal.com slash signin highlighted in red, with a note underneath showing it opens a different domain entirely.

Read the envelope,
not the letter.