Security Tools

📧 Email Triage (.eml)

Paste a full message and get the analysis a SOC analyst would do in the first minute: real routing path, SPF/DKIM/DMARC authentication with alignment, scored spoofing signals, ready-to-paste IOCs and a KQL query to hunt down the rest of the campaign. New to this? Learn to spot the flags by hand in the Anatomy of a phishing email.

🔒
100% local analysis. The message is processed in your browser with JavaScript. Nothing is uploaded, stored or sent to third parties. You can analyze real client mail without breaking your NDA.

Shortcut: Ctrl + Enter analyzes. In Outlook, drag the mail to your desktop to get the .eml; in Gmail, "Show original" → "Download original".

Frequently asked questions

What does it analyze in an email?
Upload the .eml and it gives a phishing verdict: the real message route (Received headers), SPF, DKIM and DMARC alignment, suspicious links and attachments, and IOCs ready to block.
Is the email uploaded to a server?
No. The analysis happens in your browser; the email content never leaves your device.
Why can an email "pass SPF" and still be phishing?
Because SPF validates the envelope domain, not the "From" you see. Without DMARC alignment an attacker can pass SPF with their own domain; the tool checks exactly that alignment.