Cyber Scout Phishing Analyzer

Is That Email Trying to Trick You?

Check an email for common phishing warning signs. Load a downloaded .eml file or paste redacted text, and our free analyzer examines suspicious language, links, headers, and other indicators directly in your browser. No account required, and your email stays on your device.

Spot the warning signs. Stay one step ahead.

Local onlyNo uploads, trackers, or network lookups.
ExplainableEvery finding shows evidence and points.
ConservativeA low score never means guaranteed safe.

Analyze a Suspicious Email

For the most complete analysis, download the suspicious message from your email app as an .eml file, then load it here. The file is read locally in your browser.

Maximum file size: 2 MB. You can still paste redacted email text below if you do not have an .eml file.

How do I get an .eml file?

In most email apps, open the suspicious email and look for a More menu, three-dot menu, Save As, Download Message, or Show Original option. Save the message as an .eml file, then choose it here.

Provider menus change over time. If your mailbox cannot export an .eml file directly, use the closest option for downloading the original message or showing full headers, then paste redacted text below.

Review the extracted text and redact anything sensitive before analyzing. Limit: 120,000 characters.

File loading and analysis stay disabled until you acknowledge the notice. 0 / 120,000

Concern Summary

Load a redacted .eml file or paste email text, acknowledge the notice, and run the analyzer to see warning signs here.

How it works

Paste, Review, Verify Independently

This tool checks for common warning signs in the text you provide. It does not decide whether a message is safe or malicious, and it never opens links or inspects actual attachments.

  1. LoadUse a downloaded .eml file when possible, or paste redacted email text, headers, or HTML.
  2. ReviewRead each observation, evidence excerpt, point value, and recommendation.
  3. VerifyUse official websites, apps, or known contact details instead of email-supplied instructions.

Education

Useful Terms Without the Scare Tactics

Phishing

A deceptive message designed to make you reveal information, open something risky, or send money.

Spoofing

A forged or misleading sender identity. A display name can be fake even when it looks familiar.

MFA

Multi-factor authentication adds a second proof, such as an app prompt or one-time code. Never share codes by email.

SPF, DKIM, DMARC

Email authentication checks that can help receiving systems evaluate sender legitimacy. This tool only reads reported results in pasted headers.

Suspicious Links

Shorteners, raw IP addresses, misleading text, and unusual URL structures can hide where a link goes.

Impersonation

Fraudsters may pretend to be executives, IT staff, banks, delivery services, or familiar vendors.

Private by Design

Private by Design: Your email is analyzed directly in your browser. Nothing you load or paste is uploaded to our servers or saved by Cyber Scout Labs.

The application does not use cookies, local storage, analytics, remote scripts, URL previews, file uploads, or link expansion. Your hosting provider may still process ordinary website-access metadata, such as an IP address requesting the static page files.

About Cyber Scout Labs

Cyber Scout Labs builds practical security education tools for everyday decisions. This analyzer is an educational triage aid, not a definitive determination. It cannot confirm whether a URL is malicious, independently authenticate a sender, inspect attachments, find every attack, or guarantee a message is safe.