Headers

Take a suspicious email apart and see what it is really made of.

Getting the email out of your mail app
Drop the email file here
or tap to choose one  ·  .eml, .txt, .mbox  ·  it stays on your device
or paste it
How it works: an email carries far more than the part you read. Every server that handled it stamps a Received line, three separate checks record whether the sender was permitted to use the name on the message, the links carry the destination inside layers of redirect and tracking, and the attachments announce their real type in their first few bytes regardless of what they are called. This page pulls all of that apart and looks for the specific mismatches used in invoice fraud, credential phishing and account-recovery scams, then shows the evidence behind every finding so you can disagree with it. Nothing is uploaded, no link is visited, no attachment is opened, and the preview blocks every remote image so a tracking pixel never fires. All of it runs here in the page, so a private email stays private.