Free Security Tool

Is this email
legitimate or a phishing attack?

Paste any suspicious email — headers and all. Our analyzer checks SPF, DKIM, DMARC authentication, inspects every URL, and flags the social engineering tactics criminals use to trick you.

SPF / DKIM / DMARC check URL inspection & lookalike detection Display-name spoofing detection Instant 0–100 risk score
Email Authentication
URL Inspection
Sender Verification
Content Red Flags
Analysis Verdict
Get a PDF copy of this report
We'll email the full analysis with recommendations to your inbox.
Report sent — check your inbox.
Train your team to spot these attacks in real time
SecurEveryone's live training sessions teach your team to recognize the patterns this analyzer found — before they click.
All tiers include session recording for future onboarding.
How it works

Three checks in 30 seconds

01 — Headers
Authentication Check
We parse the Authentication-Results header to read SPF (sending server authorization), DKIM (message integrity), and DMARC (domain policy alignment). Failures on all three are the single strongest signal that a message is spoofed.
02 — URLs
Link Inspection
Every URL is extracted and checked for four things: mismatched display text, URL shorteners hiding the destination, punycode/IDN lookalike domains, and suspicious paths (login, verify) on domains unrelated to the sender.
03 — Content
Red Flag Detection
Urgency language, credential-prompt phrases, attachment references, and generic greetings are all pattern-matched in the body. These are the psychological pressure points attackers exploit — we surface them plainly.