Free email forensics

Is that email really from who it says?

Drop a suspicious email and we'll read its hidden headers — the same provenance a forensic analyst checks. See where it was actually sent from on a map versus where it claims to be, whether it passed sender authentication, and what it's carrying. Free, and no signup.

Drop a suspicious email here

Save the email as a .eml or Outlook .msg file, then drag it in — or browse.

No sign-in. We keep submitted emails to improve scam detection — stored securely, never shown publicly.

  • Where it really came from — claimed vs actual sending country, on a map.
  • SPF, DKIM and DMARC results, and From / Reply-To mismatches.
  • Risky attachments flagged by name and type — we never open them.
  • Tell-tale scam signs — language that doesn't match the origin, poor spelling, and big money demands.

Your forensic read appears here

Drop an email on the left to see where it was really sent from, whether it passed authentication, and what it's carrying.

Got the text of a message instead of a file? Paste it into the message checker. Checking a website address? Use the domain checker.

How to save an email as a file

  • Outlook (desktop): open the email, then File → Save As → choose Outlook Message Format (.msg).
  • Gmail: open the email, click the three-dot menu → Download message (saves a .eml).
  • Apple Mail: select the email, then File → Save As → Raw Message Source (.eml).

What we check — and what we don't

We read the email's delivery headers to trace the route it travelled and the server that first sent it, then geolocate that server and check it against public IP-reputation sources. We compare the From, Reply-To and Return-Path addresses, check SPF, DKIM and DMARC, and list attachments by name, type and a fingerprint (hash) only. We never open or run attachments, and we never reply to or contact the sender. We keep a copy of the submission to improve scam detection and for security research — stored securely and never shown publicly (see our privacy notice).