When to use it
You have Email headers and want to check it through safe, legal, source-based research.
Email workflow
A workflow for reading headers, sender alignment, links, and attachments safely.
Passive and safe research workflow
When to use it
You have Email headers and want to check it through safe, legal, source-based research.
What you get
Email triage note, header summary, link context, and recommended response.
Safety boundary
This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.
Simple order
Keep raw headers and observation time.
Check: The original message is not altered.
Read SPF, DKIM, DMARC, and alignment.
Check: Authentication is interpreted with limits.
Separate domains, redirects, and attachments without entering data.
Check: No risky click or login is performed.
State visible indicators, uncertainty, and user-safe action.
Check: No malware or bypass instruction is included.
Real tools to open
Report language
Email header and link traces show suspicious context, but sender identity and intent require further confirmation.
Move to evidence notesSources
AlienVault OTX
Threat intelligence
Use for IOC context, reputation checks, and defensive security notes.
Open sourceCISA Cyber Hygiene Services
Data breach checks
Use for exposure checks and defensive awareness, not for profiling people.
Open sourceDNSDumpster
Domain and DNS intelligence
Use for domain ownership context, DNS records, certificates, and passive web traces.
Open sourceDNSViz
Domain and DNS intelligence
Use for domain ownership context, DNS records, certificates, and passive web traces.
Open sourceGoogle Password Checkup
Data breach checks
Use for exposure checks and defensive awareness, not for profiling people.
Open sourceHave I Been Pwned
Data breach checks
Use for exposure checks and defensive awareness, not for profiling people.
Open source