Phishing-Analyzer
Reichen Sie eine verdächtige E-Mail ein und erhalten Sie ein Urteil auf Analystenniveau — Absenderauthentifizierung, Linkintegrität, sprachliche Manipulation und Payload-Risiko — zusammengefasst in einer einzigen Kennzahl, inklusive bereits ausgearbeiteter Reaktionsmaßnahmen.
Six phases, run in order — cheapest first
Every submission passes through a sequential, non-destructive pipeline. The order is deliberate: it resolves obvious spam and legitimate traffic before spending heavy compute — like dynamic sandboxing — on anything.
Ingestion & structural parsing
A raw .eml or .msg is split into its foundational elements — transport headers, plain-text and HTML bodies, and binary attachments. Parsing is passive: nothing is rendered, nothing is executed.
Authentication verification
SPF, DKIM and DMARC results are read from the receiving gateway's headers, then checked for strict domain alignment — does the From domain actually match the domain these protocols authorised?
Link extraction & sanitization
Every hyperlink is extracted and de-obfuscated, shorteners are resolved to their true destination, and the visible display text is compared against the real href target.
Natural-language & behavioural analysis
An NLP pass reads the text for behavioural anomalies: urgent calls to action, credential-verification requests, financial manipulation themes and pretexting.
Attachment reputation & sandboxing
Attachments are hashed (SHA-256) and statically inspected for type abuse. Only files that fail static inspection are routed to the isolated sandbox — the expensive step runs last, and only when warranted.
Risk scoring & automated response
Every indicator rolls into a single 0–100 score. High-risk verdicts trigger SOAR workflows: tenant-wide quarantine, blocklist updates and SOC notification.
Weighted indicators, not a checklist
Individual indicators are weighted into one actionable metric, so analysts never burn time on low-level spam and targeted credential harvesting gets attention immediately.
Analyse a suspicious email now
The verdict, score and authentication matrix are free. Register a company account to unlock the full report — link inspection, sender intelligence, attachment analysis, the safe visual preview and the response plan.
Built to cut through noise, not add to it
The front end has one job: minimise mean time to resolution by grouping identical threats together. Every submission you make is fingerprinted into a campaign, so the queue counts unique threats — not inbox volume.
Sign in above and your live submission queue — total vs unique, verdict split and incident count — appears here.

What the report looks like
The power of deduplication
The dashboard aggregates total submissions against unique submissions. If 100 employees report the same corporate-wide campaign, the analyst sees a single card in their queue — and resolving that one card resolves all 100 reports simultaneously.
Authentication visual matrix
A clean, colour-coded grid of SPF, DKIM and DMARC status. An email claiming to be from a major SaaS platform that fails domain alignment draws the eye instantly.
Side-by-side link inspection
User-facing text sits directly beside the underlying href. When the text says Sign in to Microsoft but the target is auth-microsoft-update.xyz, the mismatch is highlighted in red.
Safe visual preview
A headless-browser screenshot of the email body lets analysts see exactly what the user saw — with scripts disabled and every outbound request blocked, so no tracking pixel ever tells the attacker you looked.
Submitted messages are handled as evidence
Never executed
Bodies are parsed as inert text and attachments are hashed, never run. The optional visual preview renders with JavaScript disabled and all outbound requests blocked.
We don't touch attacker infrastructure
Only known URL shorteners are resolved, and never into private address space. We don't fetch arbitrary links — that would tip off the attacker and turn this into an open proxy.
Stored to your account only
Reports are stored against your company account so the campaign queue can deduplicate across your reporters. Nobody else can retrieve them, and anonymous submissions never enter a tenant's queue.
Your responsibility to submit lawfully
Emails contain personal data. You confirm you're authorised to submit them; handling follows GDPR principles of minimisation and purpose limitation.
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.