Paste the source of an email you are not sure about. It checks who really sent it, where replies and links really go, whether an attachment can run code, and whether the wording is pushing you, then says what to do. Read in your browser; links are never opened.
Or paste the email’s source
Links are never opened
The email never leaves this browser
Try it offline: it still works
Example report
“URGENT: vendor payment today”
Likely phishing
Sender imitates your domain!
Link shows one site, goes to another!
Attachment hides its real type!
More in the full report●●●
Reading the headers in your browser
Checking who really sent it
Checking the addresses and links
Checking attachments and wording
Email inspection
1 Summary
What the email shows
2 The checks
3 What this could not check
A judgement from the signals listed, read in your browser. Links were never opened and attachments never run. An email can pass every check and still be a scam, for example from a real mailbox someone has broken into. Guidance, not a guarantee; see the terms.
HOW TO GET IT
The email’s source
Every mail program can show the raw message, with the headers that record who sent it. Copy all of it.
Open the emailIn Gmail on a computer, not the phone app.
Show originalThe three dots at the top right of the message, then “Show original”.
Copy to clipboardThen paste it above. Or “Download original” and drop the file in.
Open the emailIn Outlook on the web, or the new Outlook.
View message sourceThe three dots, then View, then “View message source”.
Select all and copyThen paste it above.
Open the email in its own windowDouble-click it.
File, then PropertiesThe headers are in the “Internet headers” box at the bottom.
Copy the headersPaste them above. Without the body, links and attachments are not checked.
What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, no link is opened, and no attachment is run. The report never repeats the email’s text.
QUESTIONS
Asked often
The questions people search for before they run the check.
How can I tell if an email is a phishing email?
Look at who really sent it, not the name shown: the domain after the @, spelt letter by letter, and whether your mail server's SPF, DKIM and DMARC checks passed. Then where replies and links really go, and whether it pushes you to act fast. This inspector reads all of that from the email's source and says what it finds.
How do I see the full headers of an email?
In Gmail on a computer, open the email, use the three dots and choose Show original. In Outlook on the web, the three dots, then View, then View message source. In Outlook on Windows, open the email in its own window and use File, then Properties: the headers are in the Internet headers box.
What do SPF, DKIM and DMARC results in a header mean?
They are your mail server's checks on whether the message really came from the domain it claims. A DMARC fail means it did not, and the email is very often forged. A pass proves only who owns the sending domain: scammers pass these checks from lookalike domains they registered themselves.
Is it safe to paste an email here?
The email is read in your browser and is not uploaded or stored. Links are read as text and never opened, and attachments are judged by their names and types, never run. If you ask for the report, we keep your details and the verdict, never the email's contents.
What should I do with a phishing email?
Do not click, reply or open attachments. Report it to your IT team or with your mail program's Report phishing button, then delete it. If you already clicked and typed a password, change it from the real site and turn on a second factor. If money was sent, call your bank and report it on 1930 or cybercrime.gov.in at once.
Godwit AI Labs
This report is available as a branded PDF. Use “Download the report” on the page,
or ask us for the detailed report at godwit-tech.com/contact.
One slip should not become a breach
DMARC on your domain, filtering that catches lookalikes, one button to report a suspicious email, and MFA on every mailbox, so the email that gets through costs a password reset, not a payment.