EMAIL TRIAGE / EDUCATIONAL TOOL
Read the signals.
Not the promises.
Inspect suspicious email without visiting its links. Transparent rules, explainable evidence, no uploads.
01 / Inspect an email
All six examples use reserved .example domains. They are invented, not real messages.
02 / Evidence report
Awaiting input — no risk rating yet.
Always verify independently
- Do not click links or open attachments to test an email.
- Use a saved bookmark, known app, or separately obtained phone number. Do not use contact details from the suspect message.
- Confirm payment changes with a known contact through a second channel. Report suspicious messages to your security team.
- If you shared credentials: change them through the official service and contact your security team; review MFA and active sessions.
Method and limitations
The 0–100 score is a sum of unique weighted rules after family caps, not a probability or calibrated prediction. 0–19: low indicators; 20–49: suspicious; 50–100: high indicators. Low indicators does not mean safe.
Plain text can lose real link destinations. No DNS, reputation, domain ownership, registrable-domain, attachment-content or malware verification occurs. Brand-host association is a heuristic and can flag legitimate third parties. Authentication headers can be forged; reported passes are unverified and never lower risk. Missing headers are unassessable. Rules can miss subtle scams or flag benign language. Attachment filenames are not a malware scan.
No APIs, accounts, telemetry, uploads, external images, storage or network requests. Reset clears this page's inputs and report; your clipboard and browser environment are outside this tool's control.