NuModeX MailOrigin

Check a suspicious email in your browser. The message never leaves your machine.

Paste the message here

Press Ctrl-V, or Command-V on a Mac.

Or drag a .eml file anywhere onto this panel.

Do not double-click a downloaded .eml to open it, and do not open attachments from a message you are investigating. Copying the text is safe; opening the message in a mail program is not.

Start with a real example

You do not need anything of your own yet. Open a real phishing message and see exactly what you get back - it passes every authentication check and still is not what it claims to be.

More examples

The same analysis, run on messages that are not phishing - so you can see what the tool says when it has no bad news, and how carefully it says it.

  • An ordinary message

    Nothing high-risk in it. Shows what the tool says when it has no bad news, and how carefully it says it.

  • A message copied off the screen

    No headers, because that is what the clipboard carried. Shows a partial analysis and what it can still tell you.

These are constructed examples, not captured mail. No address or domain in them belongs to anyone.

Getting the message out of your mail program

This tool reads the raw source of a message - the part your mail program hides, which carries the delivery records and the real link addresses. Every program calls it something different. Pick yours.

Which mail program are you using?

Steps

  1. Open the message.
  2. Click the three dots at the top right of the message, next to Reply.
  3. Choose Show original. A new tab opens.
  4. Click Copy to clipboard on that page. This is the easiest route there is - two clicks, and no file saved to your computer.

Then paste it into the box at the top of this page - Ctrl-V, or Command-V on a Mac.

Screen recording

A short screen recording of these steps is planned for this slot and has not been made yet. The written steps below are complete on their own.