Email Header Threat Analyzer
Paste raw headers or drop an .eml file. Get routing reconstruction, SPF/DKIM/DMARC alignment,
link forensics, and a correlated verdict — OK, Suspicious, or Likely Spam/Phishing — in seconds.
PostoChecker gives IT/IS admins fast, self-service email forensics and domain posture checks — the answers a SOC platform would give you, without deploying one.
Full command of your domain and email operations, in one admin's hands.
Automated analysis that empowers IT/IS admins to answer "is this a problem?" for a message, a domain, a report, or an IP — without doing the work by hand.
Paste raw headers or drop an .eml file. Get routing reconstruction, SPF/DKIM/DMARC alignment,
link forensics, and a correlated verdict — OK, Suspicious, or Likely Spam/Phishing — in seconds.
Turns raw DMARC aggregate (RUA) XML into a plain-language summary your team can actually read and act on — no more unopened report emails.
Coming soonOne scan covers SPF, DKIM, DMARC, MTA-STS, and BIMI presence — each graded against its IETF spec, with a combined posture score instead of a black box.
Coming soonReport and check a source IP against well-known community DNSBL / blacklist sites from a single place — built for abuse investigations and deliverability triage.
Coming soonThe Email Header Threat Analyzer runs entirely in your browser. Message bodies are never uploaded — the only outbound calls are DNS-over-HTTPS lookups against public resolvers.
Every grade cites the RFC behind it — so a verdict is never a black box.
Header findings and live domain posture blend into one 0–100 verdict — an auth-failing message
against a p=reject domain reads as forgery, not two disconnected reports.
IT/IS admins are expected to have SOC-grade visibility into their organization's email and domain security — without the SOC-grade tooling, headcount, or budget that's supposed to come with it. Just a DNS zone they own, an inbox full of things that might be phishing, and no time to become a security analyst on top of everything else on their plate.
IT/IS ops fields every spoofed invoice, every mismatched Reply-To, every DMARC report nobody's opened — they're the actual frontline of daily security operations, upstream of any SOC. Sharpen what happens there, and everything downstream gets faster and easier to act on: cleaner, better-documented findings instead of a hallway "can you check this?" starting from scratch.
The full suite launches soon — check back for the live portal.