DMARC Engine
Home/Free tools/Phishing Email Checker
Free tool · Security & threat analysis

Phishing Email Checker

Analyse a suspicious email's headers and content.

Paste a full raw email, headers and body, to scan it for common phishing signs. Everything runs in your browser, so nothing is uploaded or stored. Use this as a quick second opinion, not a final verdict.

In most clients you can open a message and choose "Show original", "View source" or "Show raw", then copy everything.

The Phishing Email Checker examines a suspicious message you paste in, reading both its headers and its visible content, and highlights the signals that separate a genuine email from an impersonation attempt. It reads the Authentication-Results header for SPF, DKIM and DMARC verdicts, compares the displayed From address against the DKIM signing domain and the Return-Path, and scans the body for the classic hallmarks of phishing such as urgent demands, mismatched links and lookalike domains.

Why authentication is the strongest signal

Phishing relies on making a message look like it came from a brand you trust. Email authentication exists precisely to expose that. A legitimate message normally carries dkim=pass with a signing domain (d=) that aligns with the visible sender, and an overall dmarc=pass. When a domain publishes DMARC at enforcement (p=quarantine or p=reject), receivers will block unauthenticated mail claiming to be from it. That is why getting your own domain to enforcement is the single best defence against being impersonated.

Reading the result and acting on it

Treat a message with suspicion when you see any of these:

  • Failed or absent authentication: spf=fail, dkim=fail or no DMARC pass for a brand that should authenticate.
  • Domain mismatch: the From brand does not align with the DKIM d= domain or the Return-Path.
  • Deceptive links: anchor text showing one domain while the underlying URL points elsewhere, or a lookalike spelling.

Never click links or open attachments in a flagged message; report it to your IT team or the impersonated brand and delete it. If your own domain is being spoofed, moving it to DMARC enforcement stops the abuse at the receiver. Our enforcement guide explains how, and DMARC Engine can run it for you.

Frequently asked questions

What does the checker actually look at?

It parses the message headers for the SPF, DKIM and DMARC verdicts and the sender identifiers, then scans the body for phishing indicators such as deceptive links, lookalike domains and urgency cues. It combines both into a plain-English risk assessment.

Can a phishing email still pass SPF or DKIM?

Yes. SPF and DKIM only prove a message was authorised by some domain, not that the domain is the brand it claims to be. Attackers often authenticate mail from a lookalike domain they own, so always check that the authenticated d= domain actually aligns with the brand in the From address.

Why is DMARC the key defence against impersonation?

DMARC ties a passing SPF or DKIM result to the visible From domain through alignment. When that domain publishes p=quarantine or p=reject, receivers junk or block messages that fail, so a spoofed message claiming to be from it does not reach the inbox.

How do I spot a lookalike sender domain?

Look for swapped, added or removed characters, such as a digit zero standing in for the letter O, or an extra hyphen. The display name can say anything, so always inspect the actual domain after the @ and compare it to the brand's real address.

I received a phishing email pretending to be my own brand. What now?

That means your domain is exploitable for spoofing, usually because DMARC is missing or still at p=none. Publish DMARC and progress it to enforcement so receivers reject the forgeries. See our enforcement guide or have DMARC Engine handle it.

Is it safe to paste a suspicious email here?

The tool analyses the text you paste to surface authentication and content red flags. Do not click any links or open attachments from the original message, and redact anything highly confidential before pasting if you are unsure.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.