MAIL FORENSICS
Paste raw email headers — or drop the whole .eml file — and get the true origin IP + location, the full relay chain with per-hop delays, SPF/DKIM/DMARC verdicts, and automatic spoof detection.
Analyze an email
API: POST /api/eh (raw=…) → JSON: origin IP + geo + source, hop chain, per-hop delays, verdicts, spoof flags. Free.
EXAMPLE FLOW — was this 'bank email' really sent by the bank?
- you get a scary email from [email protected] — open it, ⋮ → Show original, copy everything.
- you paste the headers here (or drop the .eml) and hit Analyze.
- site walks the Received chain bottom-up: the oldest hop is where the mail actually entered the internet.
- origin IP found: 185.234.72.19 — a bulletproof host in Sofia, Bulgaria · datacenter ⚠ — not your bank's infrastructure.
- verdicts come back: SPF fail · DKIM none · DMARC fail — three red tags.
- spoof flags light up: envelope-from ≠ From domain — the display name is wearing a costume.
- relay delays show the 4-second stall at a server that has no business handling bank mail.
- you verdict: phishing. Delete, report, done — and you have the origin evidence to show for it.
HOW IT WORKS
- An email's headers are its postal history — every server that touched it adds a Received line, and liars can't forge the chain reliably.
- We read the chain from the bottom (oldest) up: that first hop is the true origin, and we geolocate its IP.
- SPF/DKIM/DMARC are the domain's own authentication verdicts — fails here mean the mail didn't come from where it claims.
- Spoof markers are checked automatically: envelope sender vs display From, Reply-To hijacks, mismatched domains.
- Per-hop relay delays expose weird pit stops — legit bank mail doesn't detour through random countries.
- Everything works from pasted headers OR a dropped .eml file — the parser handles both.
JARGON — hover any chip:
Received chain SPF DKIM DMARC envelope-from .eml
FOR AGENTS ?
POST /api/eh raw=<full headers>curl -X POST https://dark0rbits.thetempleofdoom.com/api/eh --data-urlencode [email protected]Returns origin_ip, origin_geo, hops, delays, verdicts, flags. No auth needed for 20/min. · spec: /openapi.json · catalog: /llms.txt