Torito

Email Header & EML Analyzer

Review a suspicious email as evidence, not as an active message. Paste its source or open a local EML file to inspect identity fields, delivery information and content without contacting a mailbox or loading remote resources.

About Email inspectorFeatures & how to use

Inspect email headers, Received hops, MIME parts, declared authentication and links from local EML files without uploading or rendering messages.

What it can do

  • Inspect From, Reply-To, Return-Path and duplicate identity headers, with Received hops in oldest-first order.
  • Read declared SPF, DKIM and DMARC results without mistaking them for independently verified authentication.
  • Inspect MIME structure, attachment metadata, inert HTML source and extracted links. Attachments are never opened or executed.
  • Inputs are limited to 10 MiB, 256 MIME parts and 20 nesting levels. Indicator extraction uses a bounded preview and reports truncation.

How to use it

  1. Paste raw headers or message source, or select a local EML file.
  2. Choose Inspect email and review identity, authentication, hops and MIME sections.
  3. Review sensitive content before copying or downloading the local JSON report.