Email Header & Phishing Analyzer
Local · optional DNSInspect message routes, authentication assertions, risky links, attachments, and privacy-safe reports.
From: "Billing Team" <billing@example.com> To: Alex <alex@example.net> Reply-To: support@xn--paypa1-l2c.example Return-Path: <bounce@mail.example.com> Subject: =?UTF-8?B?UGF5bWVudCBub3RpY2U=?= Date: Mon, 31 Aug 2026 10:02:08 +0800 Message-ID: <demo-8301@mail.example.com> Received: from mx.example.net (mx.example.net [203.0.113.40]) by inbox.example.net with ESMTPS id 91AA for <alex@example.net>; Mon, 31 Aug 2026 10:02:08 +0800 Received: from mail.example.com (mail.example.com [198.51.100.24]) by mx.example.net with ESMTPS id 72BB; Mon, 31 Aug 2026 10:01:22 +0800 Authentication-Results: mx.example.net; spf=pass smtp.mailfrom=mail.example.com; dkim=pass header.d=example.com; dmarc=pass header.from=example.com DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; h=from:to:subject; b=demo MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="demo-boundary" --demo-boundary Content-Type: text/html; charset=UTF-8 <p>Please review your invoice at <a href="http://203.0.113.90:8080/login">the billing portal</a>.</p> --demo-boundary Content-Type: application/octet-stream; name="invoice.pdf.exe" Content-Disposition: attachment; filename="invoice.pdf.exe" Content-Transfer-Encoding: base64 ZGVtbyBvbmx5 --demo-boundary--
How to use it
- 01
Open the raw message
Paste source or import an EML or TXT file up to 10 MB. Folded headers and common encoded subjects are decoded locally.
- 02
Review evidence
Inspect chronological delivery hops, authentication assertions, address mismatches, suspicious URLs, attachments, and an explainable heuristic score.
- 03
Verify or share safely
Optionally query public DNS policy records, redact email addresses, IPs, and message IDs, then export a structured report.
Frequently asked questions
Is the email uploaded?
No. The raw message stays in your browser. Only an optional DNS check sends displayed domain names and record types to Cloudflare DNS over HTTPS.
Does an Authentication-Results pass prove a message is safe?
No. Those fields are assertions from a receiving system and are meaningful only within a trusted handling chain. A legitimate domain can also send harmful content.
Can the score confirm phishing or safety?
No. It is an explainable triage aid based on visible headers, links, and filenames, not malware scanning, reputation intelligence, or a forensic verdict.
Why is DNS checking optional?
Static header analysis is private and offline. Live SPF, DKIM, DMARC, and MX policy lookup necessarily discloses queried domain names to a DNS resolver.
Related tools
Keep working with other focused browser utilities.