A fake name on the envelope
The sender name is just text — anyone can type anything there, and nothing checks it. Phones show you that name and hide the real address completely.
.eml, then drop it above.Headers alone are enough for the sender analysis. Include the body too and you also get the link and attachment analysis.
Not a score out of ten. A verdict, what to do about it, and every separate thing that is wrong with the message.
Every email has an address you are shown and an address the servers actually spoke to. Only the second one is checked.
Each row is derived from a header in your message. Open one to see the header it came from.
Reconstructed as plain text — this page never renders a pasted email's HTML. Click any link to see where it really goes.
Each server that handled this message stamped a line on the way through. Oldest first.
Highlighted lines are the ones the findings are built on.
Anatomy of a message
A name anyone can type. Nothing anywhere checks it.
The address the computers used. Usually a completely different company, and never shown to you.
The words in a link are just words. Every one is opened up and compared against its true destination.
Windows hides the real file type, so a program can arrive looking exactly like a PDF.
Each line is something the message actually did, written out in plain words, with the exact text from the email underneath it.
What it looks for
Not one of them is a spelling mistake. All of them are sitting in the message already, and each is something a genuine email almost never does.
The sender name is just text — anyone can type anything there, and nothing checks it. Phones show you that name and hide the real address completely.
A one swapped for an l. A letter from another alphabet that looks identical. Reading carefully does not help — so it is checked character by character instead.
Every computer that passes the message along stamps the time. Read in order they are a travel history — and invented stops tend to arrive before they left.
If someone steals a real person's email account, the message really does come from them. Every automatic check passes, because nothing is fake except the person typing.
This is the case that beats every tool like this one, so rather than bury it, it is one of the built-in examples: all three checks green, the verdict still Suspicious, because the reply would go to a stranger and the message leans on urgency and secrecy. It is also why the answer is never the word "safe".
Windows hides the real file type, so a program can arrive looking exactly like a PDF. The bit that runs is the bit you were not shown.
The message looks like it came from your boss. Hit reply and it quietly goes somewhere else. That one swap is behind most invoice and gift-card scams.
[ how it works ]
About thirty fixed rules, run on your own machine. No artificial intelligence, no score out of ten, no guessing — and every answer shows you the line it came from.
step 01
In Gmail it is called Show original; in Outlook, View message source. It looks like gibberish. That is fine — paste the whole lot in.
step 02
Who really sent it, where its links go, what is attached and the route it travelled. It takes about a thousandth of a second, and nothing leaves your browser.
step 03
Open any point and it shows you the exact line in the email that proves it. That is the difference between trusting a tool and being able to check it.
Privacy
This page loads a dozen local files and then makes no further network requests. Not analytics, not fonts, not a scanning API. You can disconnect from the internet and it will keep working — which is a claim you can check in your own developer tools rather than take on trust.
That matters because every comparable tool asks you to paste your email into someone else's server. Reporting a phishing attempt shouldn't require handing a stranger the contents of your inbox.
The cost, stated plainly: DKIM signatures can't be re-verified here, because that needs a DNS lookup for the sender's public key. Return Path reads the result your mail provider already recorded.
Limits
A tool that only tells you what it caught is half a tool. Here's where this one stops.
The message is rebuilt as plain text, so nothing in it can run. Every link becomes a button that tells you its true destination.