Paste a suspicious message. Get every signal back.
Email Scan runs the full risk engine over an inbound message on demand — sender, subject, body, headers and attachments — and persists the result so the analysis can be revisited, compared and reported on.
Reply-To mismatch, Return-Path mismatch and display-name impersonation are inspected alongside content.
Filenames are checked for dangerous types and disguises; where enabled, text is extracted from an uploaded file and analysed with the body.
Every scan is retained with its full breakdown, feeding the threat overview and reporting.
A scan composes every signal service in the platform. The score is additive and each service only contributes on a positive detection, so a benign message reads as safe rather than accumulating noise.
Sensitive-data findings — card numbers, IBANs, government identifiers, confidentiality markers — are surfaced on the report but contribute no score. A message containing an invoice is not a threat because it contains an invoice, and letting data-loss findings inflate a threat verdict would corrupt both.
Submitting a scan takes you directly to its Risk Analysis page rather than a summary badge, so the reasoning is in front of you by default. Recent scans on the index link back to the same report.
Provide the sender, subject and body, plus optional headers and attachments.
Every signal service runs and returns findings.
Contributions are summed into a score, level, decision and confidence.
The full breakdown is persisted and displayed.
The outcome
A reportable, revisitable verdict on any message, with the evidence attached.
Set up your organization in minutes — no inbound migration required.