peter bassill · operator
$ cat message.eml | analyse

Email Header Analyser.

Paste a raw message. Read back the authentication results and the phishing tells. Nothing you paste is stored — it is parsed in memory and gone when the page returns.

How to get the source: Gmail → ⋮ → “Show original”. Outlook → File → Properties → Internet headers. Apple Mail → View → Message → All Headers.

What it reads

The authentication results the receiving server recorded (SPF, DKIM, DMARC and ARC), whether the visible From aligns with the envelope sender and the DKIM signing domain, the Received chain, and the ordinary phishing signals — a diverging reply-to, a display name that is really an address, a brand on an unrelated domain, punycode links, urgency in the subject. Headers can be forged where DMARC is not enforced, so a clean read is evidence, not proof.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  cve  ·  security.txt