1. Aspose.Email AI Agents
  2. Scam Email Analyzer

Scam Email Analyzer

Analyze a single .msg or .eml file (≤5 MB) and get an instant safety verdict with brief findings.

Powered by aspose.com, aspose.net and aspose.cloud

How the Scam Email Analyzer Works

The Scam Email Analyzer lets you upload a single .msg or .eml file (up to 5 MB) and instantly receives an on‑screen verdict – Safe, Suspicious, Dangerous or Unknown – together with concise findings. Only one file can be submitted at a time; a second file in the same request is rejected with “Only a single file may be uploaded”. Files of any other type are rejected with “Only .msg and .eml files are supported”, and unreadable files return “Could not parse this file — it may be corrupted or password‑protected”.

Usage Limits

Free users may analyse up to five files per day, while a paid subscription raises the limit to fifteen. When a limit is reached the tool shows a dialog that compares the free and premium tiers. After a result is displayed you can start a new analysis by clicking the “Analyze Another File” button, which resets the interface.

Verdict Determination

The verdict starts at Safe and is only raised – never lowered – by the most severe finding in the email. The four possible outcomes are:

  • Safe: no technical or AI‑driven findings raise the level.
  • Suspicious: at least one finding of Suspicious severity (e.g., SPF failure, suspicious attachment name, mismatched link display).
  • Dangerous: any Dangerous finding (e.g., DKIM or DMARC failure, macro‑enabled Office document, body‑versus‑attachment contradiction, AI‑detected impersonation).
  • Unknown: the AI review could not form a judgement and no technical checks produced a result.

Each verdict is accompanied by short tags that name the checks that triggered it. When the AI alone drives the decision the tag is ai-flagged; when the AI is simply inconclusive the tag is inconclusive. A collapsible full report contains a plain‑language narrative and a list of every individual finding, labelled with its severity (Informational, Suspicious, Dangerous) and origin (technical check or AI review).

Technical Checks

Sender Authentication

The analyzer reads the SPF, DKIM and DMARC results that were already recorded by the receiving server. No live DNS lookups are performed. A DKIM or DMARC failure is treated as Dangerous, an SPF failure as Suspicious, and the absence of any authentication record is reported as “not verifiable” without affecting the verdict. When several authentication records exist, the one closest to the recipient is used and its source server is shown in the report.

Attachment Checks

Attachment file names are scanned for 22 known executable or script extensions (e.g., .exe, .js, .vbs, .bat, .ps1, .jar, .msi, .hta, .lnk, .reg). A match is flagged as Suspicious. Double extensions such as invoice.pdf.exe are explicitly reported as “a common technique to disguise executables as documents”. Macro‑enabled Office files (.docm, .xlsm, .pptm) are also marked Suspicious. The tool compares each attachment’s actual file signature with its declared extension; a mismatch is reported as Suspicious with both the claimed and detected types listed. Modern Office archives (.docx, .xlsx) are correctly recognised and not flagged as disguised archives. Attachment contents never leave the server and are not sent to the AI model; the AI receives only the file name and declared type.

Link Checks

Every hyperlink in the email body is examined for a disparity between the displayed address and the actual target URL. When the visible text looks like a web address or domain and the two differ, the link is flagged as Suspicious and both hosts are shown. Plain call‑to‑action text such as “Click here” never triggers this check, ensuring normal buttons are not marked. Links are never visited and no external reputation service is consulted.

AI Review

In addition to the technical checks, a single AI review processes the subject, plain‑text body, sender address, sender display name, attachment list, and all technical findings. The AI looks for mismatched display names, brand‑typosquatting, look‑alike domains, and contradictions between claimed and actual attachments. Any body‑versus‑attachment contradiction is automatically classified as Dangerous. The AI generates a plain‑language narrative for the top of the full report, aimed at non‑technical users. If the AI review cannot be completed but technical checks have already yielded findings, the technical verdict is shown together with a notice that AI analysis was unavailable. If the AI cannot run and no technical findings exist, the request fails rather than returning a false “Safe” result.

Transparent Limitations

  • No live DNS re‑verification of SPF, DKIM, or DMARC records.
  • Macro‑enabled documents are flagged, but their macro code is not extracted or analysed.
  • Attachments are never executed, opened in a sandbox, or scanned by an antivirus engine.
  • Links are analysed only as text; they are not followed and no reputation database is used.

How to check MSG and EML emails for scams

STEP 1

Upload your file

Click inside the file drop area to upload your file or drag & drop it.

STEP 2

Analyze

Click on the "Analyze" button. Your file is checked against header, attachment and link forensics, then reviewed by AI.

STEP 3

Read your verdict

A verdict of Safe, Suspicious, Dangerous or Unknown appears instantly, along with tags naming what was found.

STEP 4

Open the full report

Expand the full report to read the plain-language explanation and every individual signal behind the verdict.

FAQ

Which file types can I upload?

Only .msg and .eml files up to 5 MB are accepted; any other type is rejected with “Only .msg and .eml files are supported”.

How many files can I analyze per day?

Free users can analyse up to 5 files per day, while a paid subscription raises the limit to 15 files per day. When the limit is reached the app shows a dialog comparing the free and premium tiers.

Can I trust a “Safe” verdict?

A “Safe” verdict means no technical or AI‑driven finding raised the level; it does not guarantee the email is harmless, only that the analyzer found nothing suspicious.

Why is an SPF failure only “Suspicious” while DKIM or DMARC failures are “Dangerous”?

SPF often breaks when mail is legitimately forwarded, so the app treats an SPF failure as “Suspicious”. DKIM and DMARC failures are harder to justify and are therefore classified as “Dangerous”.

What happens to the uploaded file?

The file is processed on the server, never stored permanently, and its contents are not sent to any external service.