Nobuf

EML & MIME Email Analyzer

Local MIME forensics

Inspect raw EML messages, MIME trees, safe bodies, delivery claims, links and attachments without uploading mail.

From: "Nobuf Review" <review@example.com>
To: Alex <alex@example.net>
Reply-To: support@xn--paypa1-l2c.example
Subject: =?UTF-8?B?UHJvamVjdCByZXZpZXcg4oCUIEFjdGlvbiByZXF1aXJlZA==?=
Date: Tue, 01 Sep 2026 09:15:00 +0800
Message-ID: <sample-20260901@example.com>
Received: from mail.example.com (mail.example.com [198.51.100.24]) by mx.example.net with ESMTPS id demo; Tue, 01 Sep 2026 09:15:00 +0800
Authentication-Results: mx.example.net; spf=pass smtp.mailfrom=example.com; dkim=pass header.d=example.com; dmarc=pass header.from=example.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="mixed-demo"

--mixed-demo
Content-Type: multipart/alternative; boundary="alt-demo"

--alt-demo
Content-Type: text/plain; charset=UTF-8

Please review the project. The HTML version contains demonstration risk evidence.
--alt-demo
Content-Type: text/html; charset=UTF-8

<html><body><h1>Project review</h1><p>Open <a href="http://203.0.113.90:8080/login">https://portal.example.com</a>.</p><img src="https://tracker.example/pixel.gif" width="1" height="1" alt=""></body></html>
--alt-demo--
--mixed-demo
Content-Type: application/octet-stream; name="review.pdf.exe"
Content-Disposition: attachment; filename="review.pdf.exe"
Content-Transfer-Encoding: base64

Tm9idWYgZGVtb25zdHJhdGlvbiBmaWxlLg==
--mixed-demo--

Inspect a complete email message

Paste raw message source or open an EML file to decode MIME structure, delivery evidence, body content and attachments.

No mail or attachment upload
Parsing and preview happen locally. HTML is sanitized, remote resources are blocked, and attachments are never executed.

How to use it

  1. 01

    Open or paste an EML message

    Parse bounded RFC-style message text and MIME transfer encodings locally with PostalMime.

  2. 02

    Review evidence safely

    Inspect decoded headers, MIME parts, delivery and authentication claims, disguised links, risky attachments and a remote-blocked sandbox preview.

  3. 03

    Extract and report

    Download reviewed attachments, a ZIP manifest, a structured report or a privacy-redacted EML copy.

Frequently asked questions

Does the preview contact remote servers?

The tool sanitizes HTML, removes active content, rewrites remote resources and renders the result in a restricted iframe with a deny-by-default CSP.

Does a pass result prove an email is legitimate?

No. Authentication-Results and Received headers are message claims. This offline tool preserves and analyzes them but does not independently query DNS or establish sender intent.

Can I safely open every extracted attachment?

No. Attachments are inert while analyzed here, but downloaded files may still be dangerous. Executable, macro, active-content and misleading-name patterns require deliberate confirmation.

Which standards are relevant?

The workspace follows common RFC 5322 message and RFC 2045 MIME structures while clearly labeling bounded parsing and heuristic findings.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.