邮件头与钓鱼分析器
安全工具 按需联网
无需上传邮件即可检查原始 EML、MIME 树、安全正文、投递声明、链接与附件。
From: "Nobuf Review" <review@example.com> To: Alex <alex@example.net> Reply-To: support@xn--paypa1-l2c.example Subject: =?UTF-8?B?UHJvamVjdCByZXZpZXcg4oCUIEFjdGlvbiByZXF1aXJlZA==?= Date: Tue, 01 Sep 2026 09:15:00 +0800 Message-ID: <sample-20260901@example.com> Received: from mail.example.com (mail.example.com [198.51.100.24]) by mx.example.net with ESMTPS id demo; Tue, 01 Sep 2026 09:15:00 +0800 Authentication-Results: mx.example.net; spf=pass smtp.mailfrom=example.com; dkim=pass header.d=example.com; dmarc=pass header.from=example.com MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="mixed-demo" --mixed-demo Content-Type: multipart/alternative; boundary="alt-demo" --alt-demo Content-Type: text/plain; charset=UTF-8 Please review the project. The HTML version contains demonstration risk evidence. --alt-demo Content-Type: text/html; charset=UTF-8 <html><body><h1>Project review</h1><p>Open <a href="http://203.0.113.90:8080/login">https://portal.example.com</a>.</p><img src="https://tracker.example/pixel.gif" width="1" height="1" alt=""></body></html> --alt-demo-- --mixed-demo Content-Type: application/octet-stream; name="review.pdf.exe" Content-Disposition: attachment; filename="review.pdf.exe" Content-Transfer-Encoding: base64 Tm9idWYgZGVtb25zdHJhdGlvbiBmaWxlLg== --mixed-demo--
粘贴原始消息或打开 EML,解码 MIME 结构、投递证据、正文与附件。
使用 PostalMime 在本地解析有大小限制的 RFC 风格消息与 MIME 传输编码。
检查解码邮件头、MIME 部件、投递与认证声明、伪装链接、风险附件和阻止远程资源的沙箱预览。
下载经确认的附件、带清单的 ZIP、结构化报告或隐私脱敏 EML 副本。
工具会清理 HTML、移除活动内容、改写远程资源,并在带默认拒绝 CSP 的受限 iframe 中渲染。
不能。Authentication-Results 和 Received 是消息中的声明;离线工具会保留并分析它们,但不会独立查询 DNS 或判断发送者意图。
不能。附件在本工具内保持惰性,但下载后仍可能危险;可执行文件、宏、活动内容和误导性文件名会要求明确确认。
工作区遵循常见 RFC 5322 消息与 RFC 2045 MIME 结构,同时明确标注受限解析和启发式发现。
继续使用其他专注的浏览器端工具。