Drop in a .eml or paste a raw email record and PhishAnna dissects it — sender and
recipients, SPF/DKIM/DMARC, every link (reputation, redirects, look-alikes), attachments and
behavioural red flags — fused into one explainable 0–100 verdict.
or click to browse · maximum 10 MB
SPF, DKIM and DMARC parsed from the raw headers, plus envelope-vs-From mismatches, Reply-To tricks and the sending path.
Every link is decoded, de-shortened and live-tested for redirects, compared against the sender for look-alikes, and checked against threat feeds.
File types, double extensions, macro-enabled documents, scripts and executables are flagged and hashed.
Disposable domains, brand impersonation, urgency, account threats, credential requests and financial bait — scored by heuristics.