Analyze email body, headers, and URLs
Beyond risk level, we show the evidence found and next actions separately.
Email header and body
Email Header
URL to check
Analysis results do not guarantee safety. Even if sender authentication passes, we cannot detect a compromised legitimate account or a fake page on a legitimate service.
Check results and recommended actions
The URL is not opened automatically; it is broken down as a string.
Action to take now
- Do not open URLs in the email; verify the sender name and domain.
- Even for services you recognize, verify via the official app or saved bookmarks.
Sender, reply-to, and authentication results
This will be displayed when analyzing with headers included.
URL destination and warnings
Results are extracted from the body or the URL input field.
Delivery path (Received)
The bottom is closest to the sender, but headers can be spoofed, so do not judge alone.
Your input is not sent outside your browser.
What you can do with the Suspicious Email and URL Safety Checker
We break down the sender address, reply-to, Return-Path, SPF, DKIM, and DMARC results, and delivery path that are not visible from the display name alone. URLs in the email are broken down into the actual destination domain, Unicode notation of Punycode, shortened URLs, IP addresses, unusual ports, URL parameters, and redirect parameters containing other URLs.
We do not automatically open analyzed URLs or query external services for shortened URL destinations. Your input email, headers, and URLs are processed only in your browser.
Compare From and Reply-To
Shows domain mismatches between the displayed sender address and the address used for replies.
Break down authentication results
Extract SPF, DKIM, and DMARC pass, fail, or none from Authentication-Results.
Check disguised URL
Check for Punycode, mixed scripts, lookalike characters, shortened URLs, and closeness to the official domain.
Specific actions
Shows next steps such as do not open, do not reply, check the official app, and contact internal IT.
Steps to safely check a suspicious email
- Do not click links in the emailBefore analysis, the URL is not opened, and attachments are not saved or executed.
- Show email sourceCopy the original text from Outlook’s internet headers, Gmail’s “Show original,” or similar.
- Verify the official domain through another routeCheck the correct domain in the official app, your contract documents, or the official website you typed in yourself, not in the email body.
- Review the evidence behind the resultDon’t decide based on the risk color alone; check the From and Reply-To fields, authentication results, and the actual URL host.
- Check status from the official appFor notifications about billing, delivery, or account suspension, sign in directly to the official app without using links in the email.
- Share with your IT team if neededBefore deleting the email, submit the original message with headers and receipt time according to your company’s reporting procedure.
Differences between From, Reply-To, and Return-Path
| Item | Role | Points to check |
|---|---|---|
| From | The address shown as the sender on the receiving screen | Look at the domain after @, not the display name |
| Reply-To | Reply-to address | Whether it has changed to a domain unrelated to From |
| Return-Path | The address used as the return path for delivery errors | When using a sending service, results may differ, so combine with authentication results. |
| Received | Record of passing through mail servers | Trace the delivery path from bottom to top. Look for inconsistencies in timestamps and server names. |
A difference between From and Reply-To alone does not mean fraud. Support desks, email delivery services, and helpdesk systems may legitimately differ. However, a structure where the From claims to be the billing party but replies go to an unrelated free email address is an important red flag to verify through another route.
How to read SPF, DKIM, and DMARC results
| Authentication | What to check | If not PASS |
|---|---|---|
| SPF | Whether the source IP is a server allowed by the domain | Forwarding can cause fail, so combine with DKIM and DMARC. |
| DKIM | Whether a signed email has been altered during delivery | Check for missing signatures, key issues, and body changes |
| DMARC | Consistency of From domain with SPF and DKIM | Resistance to From spoofing is reduced. Check the policy and receiving-side verdict. |
A pass indicates the email was sent according to that domain’s mechanisms, but does not guarantee the content is safe, the billing is correct, or the sender performed the action. Compromised legitimate accounts or emails abusing legitimate forms can show a pass.
Why check Punycode, lookalike domains, and shortened URLs
Internationalized domains are represented in ASCII as Punycode starting with “xn--.” This is used for legitimate Japanese domains, but also for tricks that mix Cyrillic or Greek characters resembling Latin ones to visually mimic official names. This tool shows both ASCII and Unicode notations, and flags mixed scripts and lookalike characters.
Shortened URLs cannot reveal their final destination from the original string. Since this tool does not access the network to expand them, we advise not opening them and verifying with the sender through another route. For long subdomains containing service names, check the registrable domain at the end.
URL parameters may contain email addresses, customer numbers, or authentication tokens. When sharing analysis results with third parties, mask values or use a secure internal reporting channel.
Actions to take after analysis
If “High risk” appears
Do not open links, reply, or run attachments. Even for account suspension or unpaid notices, check via the official app or your own bookmarks. For company email, report the message source and received time to your internal IT or security desk before deletion.
If “Needs review” appears
Shortened URLs, missing authentication results, and differences between From and Reply-To can occur in legitimate emails. Do not use phone numbers or links in the email; contact via the official website’s verified contact information.
If no prominent warning
This is not a safety confirmation. Check whether the request, amount, recipient, and usual contact method seem off, and do not navigate via email to pages requesting passwords or authentication codes.
Processing that does not send email and URLs externally
Header splitting, email address extraction, domain comparison, authentication result reading, Punycode conversion, URL decomposition, parameter display, and detection of dangerous characters, shortened URLs, and lookalike domains are all done in your browser. We do not send your input to WiseChecker’s processing servers, external reputation databases, URL expansion services, or generative AI.
This method does not retrieve the final destination of shortened URLs, domain registrant information, current malware status of the site, or sender IP reputation. The results screen clearly states what is not checked externally and shows only facts verifiable from the strings.
Frequently asked questions about suspicious email and URL analysis
Is the email I enter saved?
Nothing is saved or sent. Reloading the page clears your input and results.
If the analysis shows no prominent warnings, is it safe to open?
This is not a safety guarantee. Check the official app or the official website you opened yourself for the same notification.
Are all emails with different From and Reply-To addresses scams?
No. It may differ for delivery systems or support desks. Check the relationship with the organization, authentication results, and the reply-to domain together.
If SPF, DKIM, and DMARC pass, is it safe?
This indicates the email was delivered through an authenticated path, but does not guarantee the content or the sender’s actions are legitimate.
Can I see where a shortened URL redirects?
We do not expand shortened URLs because we do not make external requests. Do not open shortened URLs; check the content via the official app or another route.
Is all Punycode dangerous?
This is a legitimate mechanism also used for internationalized domains like Japanese. Check the ASCII notation, Unicode notation, mixed scripts, and match with the official domain.
Where can I view email headers?
In Gmail, use “Show original”; in Outlook, check message properties or “Message Details.” Names vary by version.
What should I send to internal IT?
Share the received time, subject, sender, the original text including headers, and what you did, following your company’s procedures. Do not send passwords or authentication codes.