MAILSCOPE
See What The Headers Actually Say.
by H3AD

Email Header Forensics: SPF, DKIM, DMARC, Hop Chain, and Spoofing Detection

Paste raw headers from any email client, SIEM export, or mail-gateway log. MAILSCOPE reconstructs the delivery path, checks authentication, and runs 21 risk checks built specifically for phishing and BEC triage. Everything is parsed right here in your browser tab, nothing is uploaded, queried, or logged, not even to an H3AD-SEC server.

21Risk Checks
0Servers Touched
100%Client-Side

HOW TO USE

  1. Copy the raw headers: Gmail → Show original, Outlook → File → Properties, Thunderbird → More → View Source, or straight out of a SIEM/mail-gateway export.
  2. Paste and analyze: drop them into RAW HEADERS and click ANALYZE, or press Ctrl+Enter. No sample data required, but LOAD SAMPLE HEADER is there if you just want to see it work first.
  3. Read top to bottom: the verdict banner gives the overall call, then auth badges, hop chain, and the numbered risk-flag list explain exactly why.
  4. Pivot or export: click any hop IP for X-VERDIKT, any hostname for DNSCOPE, the origin-IP card for a PHISHOPS handoff, or COPY ANALYSIS for a plain-text case note.

QUICK REFERENCE

CtrlEnterAnalyze

Every analysis is saved to RECENT in the sidebar (last 5, this browser only) with verdict, hop count, and flag count at a glance, so you can jump back into a prior case without re-pasting headers.

HOW THE ENGINE WORKS

  1. Unfold and tokenize. RFC 5322 continuation lines get joined back into single logical headers, then split into key/value pairs. Received, Authentication-Results, ARC-Seal, and ARC-Authentication-Results are collected as arrays since real messages carry more than one of each.
  2. Decode and normalize. RFC 2047 encoded subjects (base64 or quoted-printable, any charset) are decoded back to plain text, and From/Reply-To/Return-Path/To are split into display name, address, and domain for every mismatch check downstream.
  3. Pull authentication verdicts. SPF/DKIM/DMARC are read from the receiving server's own Authentication-Results header (falling back to Received-SPF when absent), the ARC chain is merged by instance number, and Microsoft 365's X-Forefront-Antispam-Report is parsed for SCL, connecting IP, and Microsoft's own compauth verdict when present.
  4. Reconstruct the hop chain. Every Received header is parsed for IP, from/by/protocol, and timestamp, then walked oldest to newest to compute transit time. Origin-IP resolution skips localhost and RFC1918 relay hops (a compromised host talking to its own local mail server is a common phishing-kit artifact) and prefers Microsoft 365's connecting IP when available, so the reported origin is a real public address, not a loopback picked up from an internal relay.
  5. Run the risk engine. 21 checks fire against everything parsed above: auth failures, domain mismatches, brand impersonation including combosquats like paypal-secure.net, punycode/IDN domains decoded and checked against Unicode confusables, suspicious subject patterns, date anomalies, hop anomalies, and Microsoft 365 signals.
  6. Render the verdict. HIGH, MEDIUM, LOW, or CLEAN, driven by the single worst flag found. Colors are amber, blue, and gray, never red or green, so the verdict reads the same regardless of color vision.

WHAT GETS CHECKED

Auth failuresSPF, DKIM, and DMARC results straight from the receiving server, plus ARC chain validation for forwarded or mailing-list mail.
Domain mismatchesReturn-Path, Reply-To, Message-ID, and envelope (Delivered-To / X-Original-To) checked against the From domain.
Brand impersonationDisplay name claims a known brand while the domain isn't that brand's own, catching combosquats like paypal-secure.net, not just unrelated domains.
IDN & homograph domainsPunycode domains are decoded back to Unicode and checked for Cyrillic/Greek lookalike characters against 22 known brands, not just digit substitution.
Hop chain anomaliesMissing or single-hop chains, free-mail relays in a claimed-corporate path, and sub-second hop delays that suggest bulk sending.
Microsoft 365 signalsSpam Confidence Level and compauth from X-Forefront-Antispam-Report, independent of the raw SPF/DKIM/DMARC results.

READING YOUR RESULTS

Verdict bannerHIGH/MEDIUM/LOW/CLEAN, set by the worst flag found, with a one-line SPF/DKIM/DMARC summary next to it.
Auth badgesRead from the receiving MTA's Authentication-Results header, not re-verified against DNS. Treat as a strong signal, not ground truth, a receiving server that doesn't strip untrusted headers could theoretically be fed a forged one.
Hop chainOldest to newest, with per-hop delay and total transit time. Any hop's IP pivots straight to X-VERDIKT, any hostname to DNSCOPE.
Origin IP cardThe resolved public origin, separate from the visual hop timeline, with one-click enrich and a PHISHOPS handoff pre-filled with subject, sender, and IP.
Risk flagsEvery flag numbered, with a severity badge and a plain-language reason, not just a code name.
Severity colors
HIGHStrong indicator MEDIUMWorth checking LOWMinor / informational CLEANNo flags raised