Email Phishing Detection Tool

Analyze email headers to detect phishing attempts and authentication issues. This tool works entirely in your browser—no data is sent to our servers.

How It Works

Step 1: Get Email Header

From your email client, select "View Full Headers" or "View Source" to get the complete email header.

Step 2: Paste & Analyze

Paste the email header into our analyzer and click "Analyze" for instant results.

Step 3: Review Results

Check SPF, DKIM, and DMARC authentication results and suspicious indicators.

Step 4: Take Action

Follow our recommendations to protect yourself from phishing and email-based attacks.

Email Header Analyzer

Understanding Email Authentication

SPF (Sender Policy Framework)

What it does: Verifies that the email was sent from an authorized mail server for the domain.

PASS: Email came from an authorized server.

FAIL: Email did not come from an authorized server—potential phishing.

DKIM (DomainKeys Identified Mail)

What it does: Digitally signs emails to verify they haven't been altered in transit.

PASS: Email signature is valid and authentic.

FAIL: Email signature is invalid—the message may have been modified.

DMARC (Domain-based Message Authentication)

What it does: Combines SPF and DKIM to provide comprehensive email authentication.

PASS: Email passes both SPF and DKIM checks.

FAIL: Email fails authentication—high risk of phishing or spoofing.

Common Phishing Indicators

🚨 High Risk Indicators

  • Failed authentication (SPF, DKIM, DMARC)
  • Mismatched sender and display name
  • Sender from same domain as recipient
  • Generic email clients or spoofed servers
  • Unusual originating IP addresses

⚠️ Medium Risk Indicators

  • Unusual sending patterns
  • Shortened or redirected URLs
  • Requests for sensitive information
  • Unusual attachments or downloads
  • Urgent or threatening language

Email Security Best Practices

1. Never Click Links From Suspicious Emails

Instead, navigate directly to the organization's website by typing the URL in your browser.

2. Verify Sender Identity

Contact the sender through a separate, trusted channel to verify they actually sent the email.

3. Don't Download Unexpected Attachments

Malware is often delivered through email attachments. Verify before downloading.

4. Look for Authentication Headers

Check that SPF, DKIM, and DMARC all pass. Failed authentication is a major red flag.

5. Enable Multi-Factor Authentication

MFA protects your account even if a phisher obtains your password.

6. Report Phishing Emails

Report suspicious emails to your IT department and your email provider's abuse team.

🔒 Your Privacy is Protected

All analysis is done locally in your browser. The email headers you paste are never sent to our servers or stored. Your data remains completely private and secure. This tool works offline and respects your privacy.

Need More Advanced Security?

Our comprehensive security solutions go beyond email analysis to protect your entire organization.

Book a Security Consultation