Suspicious Email & URL Safety Checker | Analyze Headers, Sender, and Links

Do not send the email or URLFrom, Reply-To, and authentication resultsPunycode, shortened URLs, and similar domainsShow actions before opening

Analyze email body, headers, and URLs

Beyond risk level, we show the evidence found and next actions separately.

On-device processing

Email header and body

Analysis results do not guarantee safety. Even if sender authentication passes, we cannot detect a compromised legitimate account or a fake page on a legitimate service.

Check results and recommended actions

Enter the content to analyze

The URL is not opened automatically; it is broken down as a string.

Check levelNot analyzed
Caveats0 items
URL0 items
Header0 items

Action to take now

  1. Do not open URLs in the email; verify the sender name and domain.
  2. Even for services you recognize, verify via the official app or saved bookmarks.
Sender, reply-to, and authentication results

This will be displayed when analyzing with headers included.

URL destination and warnings

Results are extracted from the body or the URL input field.

Delivery path (Received)

The bottom is closest to the sender, but headers can be spoofed, so do not judge alone.

Your input is not sent outside your browser.

What you can do with the Suspicious Email and URL Safety Checker

We break down the sender address, reply-to, Return-Path, SPF, DKIM, and DMARC results, and delivery path that are not visible from the display name alone. URLs in the email are broken down into the actual destination domain, Unicode notation of Punycode, shortened URLs, IP addresses, unusual ports, URL parameters, and redirect parameters containing other URLs.

We do not automatically open analyzed URLs or query external services for shortened URL destinations. Your input email, headers, and URLs are processed only in your browser.

Compare From and Reply-To

Shows domain mismatches between the displayed sender address and the address used for replies.

Break down authentication results

Extract SPF, DKIM, and DMARC pass, fail, or none from Authentication-Results.

Check disguised URL

Check for Punycode, mixed scripts, lookalike characters, shortened URLs, and closeness to the official domain.

Specific actions

Shows next steps such as do not open, do not reply, check the official app, and contact internal IT.

Steps to safely check a suspicious email

  1. Do not click links in the emailBefore analysis, the URL is not opened, and attachments are not saved or executed.
  2. Show email sourceCopy the original text from Outlook’s internet headers, Gmail’s “Show original,” or similar.
  3. Verify the official domain through another routeCheck the correct domain in the official app, your contract documents, or the official website you typed in yourself, not in the email body.
  4. Review the evidence behind the resultDon’t decide based on the risk color alone; check the From and Reply-To fields, authentication results, and the actual URL host.
  5. Check status from the official appFor notifications about billing, delivery, or account suspension, sign in directly to the official app without using links in the email.
  6. Share with your IT team if neededBefore deleting the email, submit the original message with headers and receipt time according to your company’s reporting procedure.

Differences between From, Reply-To, and Return-Path

ItemRolePoints to check
FromThe address shown as the sender on the receiving screenLook at the domain after @, not the display name
Reply-ToReply-to addressWhether it has changed to a domain unrelated to From
Return-PathThe address used as the return path for delivery errorsWhen using a sending service, results may differ, so combine with authentication results.
ReceivedRecord of passing through mail serversTrace the delivery path from bottom to top. Look for inconsistencies in timestamps and server names.

A difference between From and Reply-To alone does not mean fraud. Support desks, email delivery services, and helpdesk systems may legitimately differ. However, a structure where the From claims to be the billing party but replies go to an unrelated free email address is an important red flag to verify through another route.

How to read SPF, DKIM, and DMARC results

AuthenticationWhat to checkIf not PASS
SPFWhether the source IP is a server allowed by the domainForwarding can cause fail, so combine with DKIM and DMARC.
DKIMWhether a signed email has been altered during deliveryCheck for missing signatures, key issues, and body changes
DMARCConsistency of From domain with SPF and DKIMResistance to From spoofing is reduced. Check the policy and receiving-side verdict.

A pass indicates the email was sent according to that domain’s mechanisms, but does not guarantee the content is safe, the billing is correct, or the sender performed the action. Compromised legitimate accounts or emails abusing legitimate forms can show a pass.

Why check Punycode, lookalike domains, and shortened URLs

Internationalized domains are represented in ASCII as Punycode starting with “xn--.” This is used for legitimate Japanese domains, but also for tricks that mix Cyrillic or Greek characters resembling Latin ones to visually mimic official names. This tool shows both ASCII and Unicode notations, and flags mixed scripts and lookalike characters.

Shortened URLs cannot reveal their final destination from the original string. Since this tool does not access the network to expand them, we advise not opening them and verifying with the sender through another route. For long subdomains containing service names, check the registrable domain at the end.

URL parameters may contain email addresses, customer numbers, or authentication tokens. When sharing analysis results with third parties, mask values or use a secure internal reporting channel.

Actions to take after analysis

If “High risk” appears

Do not open links, reply, or run attachments. Even for account suspension or unpaid notices, check via the official app or your own bookmarks. For company email, report the message source and received time to your internal IT or security desk before deletion.

If “Needs review” appears

Shortened URLs, missing authentication results, and differences between From and Reply-To can occur in legitimate emails. Do not use phone numbers or links in the email; contact via the official website’s verified contact information.

If no prominent warning

This is not a safety confirmation. Check whether the request, amount, recipient, and usual contact method seem off, and do not navigate via email to pages requesting passwords or authentication codes.

Processing that does not send email and URLs externally

Header splitting, email address extraction, domain comparison, authentication result reading, Punycode conversion, URL decomposition, parameter display, and detection of dangerous characters, shortened URLs, and lookalike domains are all done in your browser. We do not send your input to WiseChecker’s processing servers, external reputation databases, URL expansion services, or generative AI.

This method does not retrieve the final destination of shortened URLs, domain registrant information, current malware status of the site, or sender IP reputation. The results screen clearly states what is not checked externally and shows only facts verifiable from the strings.

Frequently asked questions about suspicious email and URL analysis

Is the email I enter saved?

Nothing is saved or sent. Reloading the page clears your input and results.

If the analysis shows no prominent warnings, is it safe to open?

This is not a safety guarantee. Check the official app or the official website you opened yourself for the same notification.

Are all emails with different From and Reply-To addresses scams?

No. It may differ for delivery systems or support desks. Check the relationship with the organization, authentication results, and the reply-to domain together.

If SPF, DKIM, and DMARC pass, is it safe?

This indicates the email was delivered through an authenticated path, but does not guarantee the content or the sender’s actions are legitimate.

Can I see where a shortened URL redirects?

We do not expand shortened URLs because we do not make external requests. Do not open shortened URLs; check the content via the official app or another route.

Is all Punycode dangerous?

This is a legitimate mechanism also used for internationalized domains like Japanese. Check the ASCII notation, Unicode notation, mixed scripts, and match with the official domain.

Where can I view email headers?

In Gmail, use “Show original”; in Outlook, check message properties or “Message Details.” Names vary by version.

What should I send to internal IT?

Share the received time, subject, sender, the original text including headers, and what you did, following your company’s procedures. Do not send passwords or authentication codes.

Related free tools