Back to PostoChecker How it works

Every check. One intelligence layer.

Ask "is this a problem?" of whatever you're checking — and get an answer you can act on in seconds.

The flow

The same three steps, every time

Bring what you've got

Paste raw email headers, drop an .eml, enter a domain, or type in an IP. Nothing to install, nothing to deploy.

We do the analyst's work

PostoChecker reconstructs it, checks it against the standards that define email trust — SPF, DKIM, DMARC, MTA-STS, BIMI — and correlates the findings instead of leaving you a pile of raw data.

Get a clear verdict

A plain answer with the reasons behind it — so you know what's happening and what to do next, not just a score.

The tools

How each one actually works

Email Header Threat Analyzer

Turn a raw, unreadable header into a clear verdict.

Coming soon
  1. Paste or drop. Paste the headers or drop the .eml — the analysis runs in your browser.
  2. We trace and check. We reconstruct the message's true route, verify SPF/DKIM/DMARC alignment, and inspect its links for lookalikes and hidden destinations.
  3. You get a verdict. OK, Suspicious, or Likely Spam/Phishing — with the red flags that led to it.

Automated Intelligence DMARC RUA Report Card

Make the reports nobody opens actually readable.

Coming soon
  1. Feed in the reports. Add your DMARC aggregate (RUA) XML.
  2. We turn XML into English. We group every source by volume and pass/fail, then summarize it in plain language.
  3. You get an executive report card. Who's really sending as you, which senders are misconfigured, whether spoofing attempts are happening on your domain — and where transport (TLS) security is falling short.

Domain Posture Scanner

See your whole email-security posture in one scan.

Coming soon
  1. Enter a domain. One field, one pass.
  2. We grade five layers. SPF, DKIM, DMARC, MTA-STS, and BIMI — each checked against its own standard.
  3. You get a score. A single posture score, plus exactly which gaps to close first.

Dispatch Hub

Report a malicious IP to the community, in one click.

Coming soon
  1. Enter the IP. The malicious source IP you want to report.
  2. We dispatch it. One click submits it to three well-known community blacklist providers at once.
  3. It's on record. Reported across all three — helping flag it before it reaches the next admin's inbox.
In short

PostoChecker is a triage and assessment layer, not a SIEM or SOC replacement — it gets you to a fast, defensible answer. The final call stays with your team.