Take a suspicious email apart and see what it is really made of.
Getting the email out of your mail app
Best result — the whole message. Save it as a file and drop it in below. Gmail: three dots, Download message. Outlook desktop: drag the message onto your desktop, or File, Save As. Apple Mail: File, Save As, Raw Message Source. Thunderbird: right click, Save As.
Headers only still works, you just lose the links, the attachments and the wording. Gmail: three dots, Show original. Outlook on the web: three dots, View, View message details. Outlook desktop: File, Properties, the Internet headers box. Apple Mail: View, Message, All Headers. Yahoo: three dots, View raw message.
Forwarding it to yourself does not work. Forwarding rebuilds the message, so the original route and signatures are lost. Save the file or copy the headers instead.
Drop the email file here
or tap to choose one · .eml, .txt, .mbox · it stays on your device
or paste it
How it works: an email carries far more than the part you read. Every server that handled it stamps a Received line, three separate checks record whether the sender was permitted to use the name on the message, the links carry the destination inside layers of redirect and tracking, and the attachments announce their real type in their first few bytes regardless of what they are called. This page pulls all of that apart and looks for the specific mismatches used in invoice fraud, credential phishing and account-recovery scams, then shows the evidence behind every finding so you can disagree with it. Nothing is uploaded, no link is visited, no attachment is opened, and the preview blocks every remote image so a tracking pixel never fires. All of it runs here in the page, so a private email stays private.