hexscope
Open a file

Email

Is this email real?

The name and address a message shows as its sender are whatever the sender typed. What the message cannot fake as easily is in its headers: where replies go, what the servers it passed through wrote down, and whether the domain it claims to come from vouched for it. hexscope reads them from the saved message, in your browser, and says what they mean.

Check an email Try a fake bank email

1 Save the message

Most mail programs can save a message whole, as an .eml file:

  • Gmail: open the message, then ⋮ (More) → Download message.
  • Apple Mail: File → Save As…, format Raw Message Source — or drag the message to the desktop.
  • Thunderbird: File → Save As → File.

Then open the file in hexscope. Saving it does not open its links or its attachments.

2 What gives a fake away

  • Replies go somewhere else. A message from your bank whose replies go to another domain is asking you to answer someone who is not your bank.
  • The domain did not vouch for it. SPF, DKIM and DMARC are how a domain says which servers send its mail and signs it. When the checks fail for the domain in the From line, the message may not be from there.
  • Bounces go elsewhere. Mailing services do this honestly; a personal message doing it is worth a second look.

Passing is not proof. examp1e-bank.com can vouch for its own mail perfectly. Read the domain letter by letter, and when a message asks for money, a password or a code, ask the sender another way — a number you already have.

3 What your own mail says

The first server a message reaches writes down where it came from: often your home or office address, sometimes your computer's name and its address on your own network. Mail programs add their name and version, and the date line carries your time zone. hexscope shows each of these, for messages you send as much as ones you receive.

Attached files open inside hexscope, to check a photo or a document the same way before you send it on.

4 What it does not do

hexscope looks up nothing: it does not ask the domain's servers, visit links or check an address against a list. It reads what the message itself says, and the checks the receiving server recorded. Only the message's own headers are judged; a forwarded message inside it is shown, not judged.

Check an email now Nothing leaves your browser.

Message headers are in RFC 5322; SPF in RFC 7208, DKIM in RFC 6376, DMARC in RFC 7489, and the results line in RFC 8601.