Is this email really from them?

Paste the From line (and optional body) — we estimate sender-spoofing/phishing risk from the display name, domain and body, no model, no lookup.

Paste the From line (and optional body) — we estimate sender-spoofing/phishing risk from the display name, domain and body, no model, no lookup. Free with no sign-up, and the analysis runs inside your browser — files never leave your device. On our public gate (30 real + 52 AI images) it measured 96.3% at original quality and 91.5% on recompressed copies, with zero real photos confidently mislabelled as AI. Treat it as an indicator, not proof: the newest commercial generators evade every detector.

What this tool does better

Paste the sender address, display name and body of a received email, and it estimates the likelihood of sender spoofing overall. It computes this rule-based, without any AI model.

Common email-spoofing techniques

The most common is "display-name spoofing". The screen shows "Naver Support" but the real address is something unrelated like no-reply@naver-help.xyz. Mail apps usually show only the big display name, so you must expand the actual address.

Look-alike domains (naver.com → navercorp-mail.com), recently created unfamiliar domains, and a Reply-To that differs from the sender address are all spoofing signals. An urgent demand in the body ("account suspension pending, verify now") layered on top raises the risk.

What are SPF, DKIM and DMARC?

These three verify "did this domain really send this mail". SPF checks the sending server is authorised, DKIM checks the body was not forged via a signature, and DMARC sets the policy when either fails. Formal header verification happens on the mail server; this tool instead checks the sender and body signals a person can see.

So this result is not a replacement for header authentication — it is an aid that quickly catches the things people commonly miss, such as a mismatch between the display name and the domain.

Suspicious-email checklist

Frequently asked questions

Is the email content transmitted?

No. What you paste is analysed only in your browser and is never sent to a server.

Can I see the actual SPF/DKIM result?

Formal authentication is judged by the server from the raw message headers. This tool is an aid that checks the sender and body signals a person can see.

Check these next