Email check

Is this message a fraud?

Most frauds do not look like frauds — that is why they work. What gives them away is hidden in the message headers, in the part your mail program does not show you.

How it works

Paste the source of the message, or attach the .eml file.

Every mail program has a “show original” or “show headers” option somewhere. Paste that text into the form. If it is easier, save the message as .eml and attach it — that is the only route for Thunderbird and for most mobile clients.

Strong signals

One signal of this kind is enough for a verdict of “very likely fraud”.

  • the receiving server determined that DMARC did not pass
  • neither SPF nor DKIM passed
  • the sender’s domain does not recognise the server the message came from
  • the message was sent by a script on someone else’s website
  • the display name poses as a different address
  • a link says one thing and leads to another
  • the sender domain or a link domain imitates a well-known name
  • a link points to a bare IP address
  • the message contains a form asking for a password
  • an attachment is a program, has a double extension, or is an HTML page
  • the sender’s domain does not exist

Twenty-three signals in total, strong and weak.

Four outcomes

The check does not give a score or a percentage but one of four conclusions, with the list of signals that led to it.

  • Very likely fraud at least one strong signal
  • Suspicious two or more weak signals
  • No obvious alarms not a confirmation that the message is genuine
  • Cannot judge the source is incomplete or unusable

It can be proven that a message is a fraud, never that it is not.

What happens to your message

The check is built so the message stays yours.

Attachments never leave your computer

They are stripped in the browser before sending — I only need their name and size. Measured on a real example: a 7 MB attachment arrives here as 0.8 kB, and the findings are identical.

No link is ever opened

I compare what a link says with where it points, but I do not visit it. Opening it would confirm to the sender that you read the message — which is exactly what a fraudster is waiting for.

The message text is not stored

The check runs on my server and the content of the message is kept nowhere. If the check recognises a fraud, I record the sender, the subject and the list of signals — without the message text — so I know which frauds are circulating.

No sign-up and no code

Unlike the website check, this needs no confirmation at all. Paste the source and the answer is on screen straight away.

Got a message you are unsure about?

Paste its source. No sign-up, no code, an answer straight away.

Check a suspicious message