EML & MIME Email Analyzer
Local MIME forensicsInspect raw EML messages, MIME trees, safe bodies, delivery claims, links and attachments without uploading mail.
From: "Nobuf Review" <review@example.com> To: Alex <alex@example.net> Reply-To: support@xn--paypa1-l2c.example Subject: =?UTF-8?B?UHJvamVjdCByZXZpZXcg4oCUIEFjdGlvbiByZXF1aXJlZA==?= Date: Tue, 01 Sep 2026 09:15:00 +0800 Message-ID: <sample-20260901@example.com> Received: from mail.example.com (mail.example.com [198.51.100.24]) by mx.example.net with ESMTPS id demo; Tue, 01 Sep 2026 09:15:00 +0800 Authentication-Results: mx.example.net; spf=pass smtp.mailfrom=example.com; dkim=pass header.d=example.com; dmarc=pass header.from=example.com MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="mixed-demo" --mixed-demo Content-Type: multipart/alternative; boundary="alt-demo" --alt-demo Content-Type: text/plain; charset=UTF-8 Please review the project. The HTML version contains demonstration risk evidence. --alt-demo Content-Type: text/html; charset=UTF-8 <html><body><h1>Project review</h1><p>Open <a href="http://203.0.113.90:8080/login">https://portal.example.com</a>.</p><img src="https://tracker.example/pixel.gif" width="1" height="1" alt=""></body></html> --alt-demo-- --mixed-demo Content-Type: application/octet-stream; name="review.pdf.exe" Content-Disposition: attachment; filename="review.pdf.exe" Content-Transfer-Encoding: base64 Tm9idWYgZGVtb25zdHJhdGlvbiBmaWxlLg== --mixed-demo--
Inspect a complete email message
Paste raw message source or open an EML file to decode MIME structure, delivery evidence, body content and attachments.
How to use it
- 01
Open or paste an EML message
Parse bounded RFC-style message text and MIME transfer encodings locally with PostalMime.
- 02
Review evidence safely
Inspect decoded headers, MIME parts, delivery and authentication claims, disguised links, risky attachments and a remote-blocked sandbox preview.
- 03
Extract and report
Download reviewed attachments, a ZIP manifest, a structured report or a privacy-redacted EML copy.
Frequently asked questions
Does the preview contact remote servers?
The tool sanitizes HTML, removes active content, rewrites remote resources and renders the result in a restricted iframe with a deny-by-default CSP.
Does a pass result prove an email is legitimate?
No. Authentication-Results and Received headers are message claims. This offline tool preserves and analyzes them but does not independently query DNS or establish sender intent.
Can I safely open every extracted attachment?
No. Attachments are inert while analyzed here, but downloaded files may still be dangerous. Executable, macro, active-content and misleading-name patterns require deliberate confirmation.
Which standards are relevant?
The workspace follows common RFC 5322 message and RFC 2045 MIME structures while clearly labeling bounded parsing and heuristic findings.
Related tools
Keep working with other focused browser utilities.