DKIM Signature
The sending server attaches a cryptographic signature covering the email's headers and body. The tool fetches the matching public key and recomputes the signature — if anything was changed after sending, the check fails.
SPF Policy
Every domain publishes a list of mail servers allowed to send on its behalf. The tool reads that list and compares it with the IP that actually delivered the message.
DMARC Alignment
The domain's owner declares what should happen when checks fail — accept, quarantine, or reject. The tool reports the policy and checks whether the visible From address aligns with the authenticated domain.
Sender Identity
Phishing emails routinely fake the visible display name — a message signed "PayPal Security" <random@somewhere.tld> reads as PayPal in most clients. The tool compares display name with the actual sending domain and flags mismatches.
Lookalike Domains
Attackers register domains that look almost identical to a real one — paypa1.com, microsoft.com (with a Cyrillic o), bank-secure.com. The tool inspects the sender domain for character substitutions, added words and mixed alphabets.
IP Reputation
The server that delivered the message is checked against several public blocklists used by mail operators worldwide. Presence on those lists is a strong indicator the address has been used to send spam, phishing or malware.
Domain Age
Brand-new domains are disproportionately used in scams — a domain registered three days before the message arrives is a red flag, especially when it imitates a well-known name. The tool reads the registration date from public domain registries (RDAP).
Reply-To Mismatch
A message can declare a different address for replies than the one it was sent from. That is legitimate for newsletters and helpdesks, but in phishing it routinely redirects victims to a free webmail account controlled by the attacker.
Link Inspection
Visible link text versus actual URL, redirect chains, link-shortener usage and IDN homograph attacks are all flagged. We never visit the links — only analyse them statically.
Sender network
We check whether any server in the message's delivery path belongs to a VPN provider or a Tor exit node. Legitimate mail rarely travels through anonymizing networks — in phishing it's a common way to hide the real origin.
BIMI
Brand Indicators for Message Identification — checks whether the sender's domain publishes a BIMI record with a logo, and validates any attached Mark Certificate (VMC). Displayed as a brand avatar in supporting mail clients.
DKIM Signature
The sending server attaches a cryptographic signature covering the email's headers and body. The tool fetches the matching public key and recomputes the signature — if anything was changed after sending, the check fails.
SPF Policy
Every domain publishes a list of mail servers allowed to send on its behalf. The tool reads that list and compares it with the IP that actually delivered the message.
DMARC Alignment
The domain's owner declares what should happen when checks fail — accept, quarantine, or reject. The tool reports the policy and checks whether the visible From address aligns with the authenticated domain.
Sender Identity
Phishing emails routinely fake the visible display name — a message signed "PayPal Security" <random@somewhere.tld> reads as PayPal in most clients. The tool compares display name with the actual sending domain and flags mismatches.
Lookalike Domains
Attackers register domains that look almost identical to a real one — paypa1.com, microsoft.com (with a Cyrillic o), bank-secure.com. The tool inspects the sender domain for character substitutions, added words and mixed alphabets.
IP Reputation
The server that delivered the message is checked against several public blocklists used by mail operators worldwide. Presence on those lists is a strong indicator the address has been used to send spam, phishing or malware.
Domain Age
Brand-new domains are disproportionately used in scams — a domain registered three days before the message arrives is a red flag, especially when it imitates a well-known name. The tool reads the registration date from public domain registries (RDAP).
Reply-To Mismatch
A message can declare a different address for replies than the one it was sent from. That is legitimate for newsletters and helpdesks, but in phishing it routinely redirects victims to a free webmail account controlled by the attacker.
Link Inspection
Visible link text versus actual URL, redirect chains, link-shortener usage and IDN homograph attacks are all flagged. We never visit the links — only analyse them statically.
Sender network
We check whether any server in the message's delivery path belongs to a VPN provider or a Tor exit node. Legitimate mail rarely travels through anonymizing networks — in phishing it's a common way to hide the real origin.
BIMI
Brand Indicators for Message Identification — checks whether the sender's domain publishes a BIMI record with a logo, and validates any attached Mark Certificate (VMC). Displayed as a brand avatar in supporting mail clients.
DKIM Signature
The sending server attaches a cryptographic signature covering the email's headers and body. The tool fetches the matching public key and recomputes the signature — if anything was changed after sending, the check fails.
SPF Policy
Every domain publishes a list of mail servers allowed to send on its behalf. The tool reads that list and compares it with the IP that actually delivered the message.
DMARC Alignment
The domain's owner declares what should happen when checks fail — accept, quarantine, or reject. The tool reports the policy and checks whether the visible From address aligns with the authenticated domain.
Sender Identity
Phishing emails routinely fake the visible display name — a message signed "PayPal Security" <random@somewhere.tld> reads as PayPal in most clients. The tool compares display name with the actual sending domain and flags mismatches.
Lookalike Domains
Attackers register domains that look almost identical to a real one — paypa1.com, microsoft.com (with a Cyrillic o), bank-secure.com. The tool inspects the sender domain for character substitutions, added words and mixed alphabets.
IP Reputation
The server that delivered the message is checked against several public blocklists used by mail operators worldwide. Presence on those lists is a strong indicator the address has been used to send spam, phishing or malware.
Domain Age
Brand-new domains are disproportionately used in scams — a domain registered three days before the message arrives is a red flag, especially when it imitates a well-known name. The tool reads the registration date from public domain registries (RDAP).
Reply-To Mismatch
A message can declare a different address for replies than the one it was sent from. That is legitimate for newsletters and helpdesks, but in phishing it routinely redirects victims to a free webmail account controlled by the attacker.
Link Inspection
Visible link text versus actual URL, redirect chains, link-shortener usage and IDN homograph attacks are all flagged. We never visit the links — only analyse them statically.
Sender network
We check whether any server in the message's delivery path belongs to a VPN provider or a Tor exit node. Legitimate mail rarely travels through anonymizing networks — in phishing it's a common way to hide the real origin.
BIMI
Brand Indicators for Message Identification — checks whether the sender's domain publishes a BIMI record with a logo, and validates any attached Mark Certificate (VMC). Displayed as a brand avatar in supporting mail clients.
DKIM Signature
The sending server attaches a cryptographic signature covering the email's headers and body. The tool fetches the matching public key and recomputes the signature — if anything was changed after sending, the check fails.
SPF Policy
Every domain publishes a list of mail servers allowed to send on its behalf. The tool reads that list and compares it with the IP that actually delivered the message.
DMARC Alignment
The domain's owner declares what should happen when checks fail — accept, quarantine, or reject. The tool reports the policy and checks whether the visible From address aligns with the authenticated domain.
Sender Identity
Phishing emails routinely fake the visible display name — a message signed "PayPal Security" <random@somewhere.tld> reads as PayPal in most clients. The tool compares display name with the actual sending domain and flags mismatches.
Lookalike Domains
Attackers register domains that look almost identical to a real one — paypa1.com, microsoft.com (with a Cyrillic o), bank-secure.com. The tool inspects the sender domain for character substitutions, added words and mixed alphabets.
IP Reputation
The server that delivered the message is checked against several public blocklists used by mail operators worldwide. Presence on those lists is a strong indicator the address has been used to send spam, phishing or malware.
Domain Age
Brand-new domains are disproportionately used in scams — a domain registered three days before the message arrives is a red flag, especially when it imitates a well-known name. The tool reads the registration date from public domain registries (RDAP).
Reply-To Mismatch
A message can declare a different address for replies than the one it was sent from. That is legitimate for newsletters and helpdesks, but in phishing it routinely redirects victims to a free webmail account controlled by the attacker.
Link Inspection
Visible link text versus actual URL, redirect chains, link-shortener usage and IDN homograph attacks are all flagged. We never visit the links — only analyse them statically.
Sender network
We check whether any server in the message's delivery path belongs to a VPN provider or a Tor exit node. Legitimate mail rarely travels through anonymizing networks — in phishing it's a common way to hide the real origin.
BIMI
Brand Indicators for Message Identification — checks whether the sender's domain publishes a BIMI record with a logo, and validates any attached Mark Certificate (VMC). Displayed as a brand avatar in supporting mail clients.