Threat console
Email file (.eml or .msg)
Investigate in seconds.
Upload a saved email file from Gmail, Outlook or Apple Mail for full header, body and attachment analysis.
What would you like to analyze?
AI-poweredBacked by our threat intelligence datasets for sharper accuracy.
Upload a saved email file exported from Gmail, Outlook or Apple Mail.
Step 02 · Results
Awaiting inputAnalysis verdict
Run an analysis to surface the live verdict and evidence here.
Ready when you are.
Drop in a URL, message, or file above to populate your analysis verdict here.
- Risk score with confidence band
- Key signals and evidence summary
- Recommended next steps to stay safe
ThreatSnaps analyses are AI-assisted guidance, not legal or financial advice. Always verify through official channels.
About this checker
Saving a suspicious email as a file preserves the full headers, authentication results and attachments that a copy-paste loses. Upload an .eml or .msg export and ThreatSnaps inspects SPF, DKIM, DMARC, the sending infrastructure, body content and any links so you get a complete forensic picture.
Red flags to watch for
- SPF, DKIM or DMARC fails or is missing for the claimed sender domain.
- Received-from chain originates from a country or provider unrelated to the brand.
- Attachment is a macro-enabled Office file, a password-protected archive or an HTML smuggling page.
What to do if you were targeted
- Do not open attachments outside a sandbox. Treat password-protected archives as hostile by default.
- Share the .eml with your incident-response team for indicator extraction.
- Block the sender domain and similar lookalikes at your mail gateway.
Frequently asked questions
How do I export an email as .eml or .msg?
In Gmail, choose Show original then download. In Outlook, drag the message to your desktop. In Apple Mail, File then Save As and pick Raw Message Source.
Are attachments executed?
No. The analyzer inspects metadata and content statically. Nothing is executed.
What file size is supported?
Email exports up to a few megabytes are supported, which covers virtually all real-world phishing messages.