Godwit AI Labs Talk to us

Home › Free tools › Suspicious email inspector

Is this email what it says it is?

Paste the source of an email you are not sure about. It checks who really sent it, where replies and links really go, whether an attachment can run code, and whether the wording is pushing you, then says what to do. Read in your browser; links are never opened.

Or paste the email’s source
  • Links are never opened
  • The email never leaves this browser
  • Try it offline: it still works
HOW TO GET IT

The email’s source

Every mail program can show the raw message, with the headers that record who sent it. Copy all of it.

  1. Open the emailIn Gmail on a computer, not the phone app.
  2. Show originalThe three dots at the top right of the message, then “Show original”.
  3. Copy to clipboardThen paste it above. Or “Download original” and drop the file in.

What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, no link is opened, and no attachment is run. The report never repeats the email’s text.

QUESTIONS

Asked often

The questions people search for before they run the check.

How can I tell if an email is a phishing email?

Look at who really sent it, not the name shown: the domain after the @, spelt letter by letter, and whether your mail server's SPF, DKIM and DMARC checks passed. Then where replies and links really go, and whether it pushes you to act fast. This inspector reads all of that from the email's source and says what it finds.

How do I see the full headers of an email?

In Gmail on a computer, open the email, use the three dots and choose Show original. In Outlook on the web, the three dots, then View, then View message source. In Outlook on Windows, open the email in its own window and use File, then Properties: the headers are in the Internet headers box.

What do SPF, DKIM and DMARC results in a header mean?

They are your mail server's checks on whether the message really came from the domain it claims. A DMARC fail means it did not, and the email is very often forged. A pass proves only who owns the sending domain: scammers pass these checks from lookalike domains they registered themselves.

Is it safe to paste an email here?

The email is read in your browser and is not uploaded or stored. Links are read as text and never opened, and attachments are judged by their names and types, never run. If you ask for the report, we keep your details and the verdict, never the email's contents.

What should I do with a phishing email?

Do not click, reply or open attachments. Report it to your IT team or with your mail program's Report phishing button, then delete it. If you already clicked and typed a password, change it from the real site and turn on a second factor. If money was sent, call your bank and report it on 1930 or cybercrime.gov.in at once.

One slip should not become a breach

DMARC on your domain, filtering that catches lookalikes, one button to report a suspicious email, and MFA on every mailbox, so the email that gets through costs a password reset, not a payment.