FREE EMAIL PHISHING CHECKER

Is this email safe?

Paste a suspicious message or full email header to check technical warning signs in plain English. Analysis runs locally in your browser.

You can paste the full header, message text, or both. More header information usually produces a better assessment.

Analyzed locally in this browser

Your assessment will appear here. Pasted content is treated as untrusted text.

What the Email Analyzer checks

The local analyzer reviews available SPF, DKIM, and DMARC results, sender-domain alignment, Reply-To, Return-Path, domain impersonation, lookalike domains, suspicious links, and other technical warning signs.

Authentication is not a safety guarantee. Passing SPF, DKIM, and DMARC means a message was authorized for the domain it used. It does not prove that the domain belongs to a claimed organization or that a request for money, passwords, MFA codes, or account changes is legitimate.

For a stronger assessment, include the full header

Message text alone may reveal obvious warning language, but a full header provides authentication and routing evidence. See how to view email headers, or read our guide on how to tell if an email is phishing.

Verify sensitive requests independently

For payments, banking changes, credentials, MFA codes, payroll, or account recovery, contact the person or organization using a phone number, website, app, or contact method you already trust. Do not rely only on details provided inside the message.