Uploading EML File...

Extracting artifacts and querying VirusTotal. This may take a moment.

EML Phishing Inspector

🔄 New Analysis

Automated SOC triage tool for .eml files. Extracts headers, detects typosquatting & brand impersonation, queries VirusTotal, safely renders email bodies, and unpacks hidden PDF links.

⚠️ Warning: Using the placeholder VT API key. Create a config.php one directory above with your real key.

How It Works

Upload an .eml file using the panel on the right. The inspector will automatically:

  • Parse and display all email headers with hop-by-hop routing
  • Run SPF, DKIM, and DMARC authentication checks
  • Detect typosquatted domains & brand impersonation
  • Query VirusTotal for all URLs, domains, and file hashes
  • Neutralize tracking pixels and block external images
  • Extract hyperlinks from PDF attachments
  • Generate a pre-populated SOC incident report

Upload EML File

Select an .eml file exported from your mail client or email gateway.

No file selected
  • All processing happens server-side — no data sent to third parties except VirusTotal
  • Scripts in rendered emails are disabled via sandbox
  • External images & tracking pixels are blocked by default