mailcheck.app

Free in-browser tool that checks whether an email is genuine — or a phishing attempt.

Is this email really from who it says ?

Drop in the email you want to check. We'll tell you whether it really came from the sender you see, or whether someone is impersonating them — in plain language, with the reasons why.

How do I find the email in my mailbox ?

Pick how you read your mail and which provider you use. We will walk through the four taps it takes to save the raw message and drop it back into the verifier.

Device
PROVIDER
01 / 02 Gmail

Open the message

In the Inbox list, click the message you want to check to open it.

Two answers, not one verdict.

One email, two independent checks: is it really from them — and is it a scam? They are not the same question.

Is it a scam?

Spot the trap before you click

Does this email look like a phishing or scam attempt?
Likely phishing

Multiple strong signals indicate this is likely a phishing or scam attempt.

  • Sending IP on a known blocklist
  • Domain registered 3 days ago
  • Reply-to points to a different domain

A message that pressures you, a login link, an invoice, or a sudden “we’ve changed our bank account”. Before you click, pay, or forward it to finance, check whether the sender is real and where the links actually lead.

Is it really them?

Prove it — beyond doubt

Does this email really come from the sender shown in the "From" field?
Sender verified

Sender identity cryptographically confirmed by the example.com server.

  • DKIM signature valid
  • SPF aligned with the sender domain
  • DMARC policy passed

You need to show — to a counterparty, an employer or a court — that a message really came from the stated sender and nobody altered it on the way. We verify the cryptographic signature (DKIM) that settles it.

Three steps to a verdict

Upload the email

Drop an .eml file or paste raw email source including all headers. Nothing is uploaded — the parser runs in your browser.

We analyse it

The tool fetches the sender's public keys and domain policies, recomputes the cryptographic signatures and runs heuristic checks on the headers.

You get the result

One of three verdicts — likely phishing, likely genuine, or inconclusive — with the underlying signals broken out so you can read why.

What we check

A dozen automatic checks run on every message. Each signal is reported separately — no single magic score. You can see whether the verdict rests on one strong cryptographic proof or a pile of softer red flags.

How is the tool built?

Four design decisions that shape what this tool can and can't see.

Runs locally

The analysis runs entirely in your browser. The email file is never uploaded — only public lookups about domains and IP addresses go out, never the message itself.

Per-signature detail

We show each cryptographic signature separately and label whether it was added by the sender's own domain or a third-party relay such as Amazon SES or SendGrid — not just a single overall pass/fail.

No accounts

No sign-up, no account, no history kept. Reload the page and the analysis is gone — there is nothing on a server to leak.

Plain & advanced

Two reading modes: a plain-language verdict for non-technical users, and an advanced mode that exposes raw authentication headers, domain records and route details for incident responders.

Where your email goes

The message file is opened and parsed locally in your browser. Its contents, headers and attachments never leave your device. The tool only sends public lookups about domains and IP addresses — never the message body or subject.

no upload no account