Clicking through the UI to evaluate phishing reports gets old fast. If you've got a shared phishing inbox or a SOAR pipeline, you want each email analyzed automatically, and Blue Lantern's API gives you that.
This post walks through the end-to-end flow: submit an .eml file, poll for completion, fetch the result.
Prerequisites
- A paid seat with API access and a Blue Lantern API key. Check current pricing.
- A scripting environment (we'll use
curlhere, but anything that speaks HTTP works). - Each email under 4.5 MB.
Submitting an email
Pass the .eml file to the /runs endpoint with the EMAILANALYZER tool:
curl --location 'https://api.bluelanternsecurity.io/runs' \
--header 'Authorization: [API KEY]' \
--form 'tool="EMAILANALYZER"' \
--form 'checkCost="false"' \
--form 'file=@"[PATH TO EML]"'
The response includes a jobId you'll use to track and retrieve the analysis.
Polling for completion
Use the jobId to check status against /runs/[JOB ID]. The job stays in a non-COMPLETE state until results are ready, with processing time varying by job. Handle error states rather than polling indefinitely.
curl --location 'https://api.bluelanternsecurity.io/runs/[JOB ID]' \
--header 'Authorization: [API KEY]'
Fetching the analysis
Once the run is COMPLETE, POST to /results with the job ID:
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [API KEY]' \
--data '{"jobId": "[JOB ID]"}'
What you get back
The result has two layers:
- A check summary across the email's headers, body, links, sender domain and attachment types. The documented example includes 22 checks; inspect the actual returned checks rather than assuming every response has a fixed count.
- A details object with the underlying evidence: SPF/DKIM/DMARC results, routing hops, lookalike domains, anchor-text mismatches, attachment metadata, and WHOIS-derived domain age.
The Checks_failed count can help prioritize review, but it is not a phishing probability or an automatic disposition. Inspect the details evidence and keep missing, failed or incomplete analyses unresolved. Attachment-type checks do not establish that attachment contents are safe.
A few things to know
- Retention. Submitted emails are kept for at most one day. Reports are retained for exactly one week and are accessible only to the generating user. See the Privacy Policy.
- Scope. Emails are processed for phishing-related signatures only.
For file requirements and interpretation, see Is This Email a Scam?. Use the API to collect evidence and route cases; independently verify consequential requests before acting.