Nobuf

Email Header & Phishing Analyzer

Local · optional DNS

Inspect message routes, authentication assertions, risky links, attachments, and privacy-safe reports.

EML and raw RFC 5322 source · up to 10 MB
From: "Billing Team" <billing@example.com>
To: Alex <alex@example.net>
Reply-To: support@xn--paypa1-l2c.example
Return-Path: <bounce@mail.example.com>
Subject: =?UTF-8?B?UGF5bWVudCBub3RpY2U=?=
Date: Mon, 31 Aug 2026 10:02:08 +0800
Message-ID: <demo-8301@mail.example.com>
Received: from mx.example.net (mx.example.net [203.0.113.40]) by inbox.example.net with ESMTPS id 91AA for <alex@example.net>; Mon, 31 Aug 2026 10:02:08 +0800
Received: from mail.example.com (mail.example.com [198.51.100.24]) by mx.example.net with ESMTPS id 72BB; Mon, 31 Aug 2026 10:01:22 +0800
Authentication-Results: mx.example.net; spf=pass smtp.mailfrom=mail.example.com; dkim=pass header.d=example.com; dmarc=pass header.from=example.com
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; h=from:to:subject; b=demo
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="demo-boundary"

--demo-boundary
Content-Type: text/html; charset=UTF-8

<p>Please review your invoice at <a href="http://203.0.113.90:8080/login">the billing portal</a>.</p>
--demo-boundary
Content-Type: application/octet-stream; name="invoice.pdf.exe"
Content-Disposition: attachment; filename="invoice.pdf.exe"
Content-Transfer-Encoding: base64

ZGVtbyBvbmx5
--demo-boundary--
The raw email stays in this browser. Live DNS checks are separate, explicit, and disclose only the shown domains and record types.

How to use it

  1. 01

    Open the raw message

    Paste source or import an EML or TXT file up to 10 MB. Folded headers and common encoded subjects are decoded locally.

  2. 02

    Review evidence

    Inspect chronological delivery hops, authentication assertions, address mismatches, suspicious URLs, attachments, and an explainable heuristic score.

  3. 03

    Verify or share safely

    Optionally query public DNS policy records, redact email addresses, IPs, and message IDs, then export a structured report.

Frequently asked questions

Is the email uploaded?

No. The raw message stays in your browser. Only an optional DNS check sends displayed domain names and record types to Cloudflare DNS over HTTPS.

Does an Authentication-Results pass prove a message is safe?

No. Those fields are assertions from a receiving system and are meaningful only within a trusted handling chain. A legitimate domain can also send harmful content.

Can the score confirm phishing or safety?

No. It is an explainable triage aid based on visible headers, links, and filenames, not malware scanning, reputation intelligence, or a forensic verdict.

Why is DNS checking optional?

Static header analysis is private and offline. Live SPF, DKIM, DMARC, and MX policy lookup necessarily discloses queried domain names to a DNS resolver.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.