← Back to all posts

Automate Email Analysis with the Blue Lantern API

Clicking through the UI to evaluate phishing reports gets old fast. If you've got a shared phishing inbox or a SOAR pipeline, you want each email analyzed automatically, and Blue Lantern's API gives you that.

This post walks through the end-to-end flow: submit an .eml file, poll for completion, fetch the result.

Prerequisites

  • A paid seat with API access and a Blue Lantern API key. Check current pricing.
  • A scripting environment (we'll use curl here, but anything that speaks HTTP works).
  • Each email under 4.5 MB.

Submitting an email

Pass the .eml file to the /runs endpoint with the EMAILANALYZER tool:

curl --location 'https://api.bluelanternsecurity.io/runs' \
  --header 'Authorization: [API KEY]' \
  --form 'tool="EMAILANALYZER"' \
  --form 'checkCost="false"' \
  --form 'file=@"[PATH TO EML]"'

The response includes a jobId you'll use to track and retrieve the analysis.

Polling for completion

Use the jobId to check status against /runs/[JOB ID]. The job stays in a non-COMPLETE state until results are ready, with processing time varying by job. Handle error states rather than polling indefinitely.

curl --location 'https://api.bluelanternsecurity.io/runs/[JOB ID]' \
  --header 'Authorization: [API KEY]'

Fetching the analysis

Once the run is COMPLETE, POST to /results with the job ID:

curl --location 'https://api.bluelanternsecurity.io/results' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: [API KEY]' \
  --data '{"jobId": "[JOB ID]"}'

What you get back

The result has two layers:

  • A check summary across the email's headers, body, links, sender domain and attachment types. The documented example includes 22 checks; inspect the actual returned checks rather than assuming every response has a fixed count.
  • A details object with the underlying evidence: SPF/DKIM/DMARC results, routing hops, lookalike domains, anchor-text mismatches, attachment metadata, and WHOIS-derived domain age.

The Checks_failed count can help prioritize review, but it is not a phishing probability or an automatic disposition. Inspect the details evidence and keep missing, failed or incomplete analyses unresolved. Attachment-type checks do not establish that attachment contents are safe.

A few things to know

  • Retention. Submitted emails are kept for at most one day. Reports are retained for exactly one week and are accessible only to the generating user. See the Privacy Policy.
  • Scope. Emails are processed for phishing-related signatures only.

For file requirements and interpretation, see Is This Email a Scam?. Use the API to collect evidence and route cases; independently verify consequential requests before acting.