Threat console

Email file (.eml or .msg)
Investigate in seconds.

Upload a saved email file from Gmail, Outlook or Apple Mail for full header, body and attachment analysis.

01Input
02Results

What would you like to analyze?

AI-powered

Or pick a surface
Web & Links
Messages & Chats
Files & Apps
Identity & Payments

Upload a saved email file exported from Gmail, Outlook or Apple Mail.

Zero retention
Submissions are never stored.
Encrypted
TLS-secured in transit.
Live verdicts
20 free analyses / day

Step 02 · Results

Awaiting input

Analysis verdict

Run an analysis to surface the live verdict and evidence here.

Ready when you are.

Drop in a URL, message, or file above to populate your analysis verdict here.

  • Risk score with confidence band
  • Key signals and evidence summary
  • Recommended next steps to stay safe

ThreatSnaps analyses are AI-assisted guidance, not legal or financial advice. Always verify through official channels.

About this checker

Saving a suspicious email as a file preserves the full headers, authentication results and attachments that a copy-paste loses. Upload an .eml or .msg export and ThreatSnaps inspects SPF, DKIM, DMARC, the sending infrastructure, body content and any links so you get a complete forensic picture.

Red flags to watch for

  • SPF, DKIM or DMARC fails or is missing for the claimed sender domain.
  • Received-from chain originates from a country or provider unrelated to the brand.
  • Attachment is a macro-enabled Office file, a password-protected archive or an HTML smuggling page.

What to do if you were targeted

  • Do not open attachments outside a sandbox. Treat password-protected archives as hostile by default.
  • Share the .eml with your incident-response team for indicator extraction.
  • Block the sender domain and similar lookalikes at your mail gateway.

Frequently asked questions

How do I export an email as .eml or .msg?

In Gmail, choose Show original then download. In Outlook, drag the message to your desktop. In Apple Mail, File then Save As and pick Raw Message Source.

Are attachments executed?

No. The analyzer inspects metadata and content statically. Nothing is executed.

What file size is supported?

Email exports up to a few megabytes are supported, which covers virtually all real-world phishing messages.

Related checkers