Received an email you are unsure about? Blue Lantern Security Email Analyzer checks the original message for suspicious sender details, authentication results, content and links, then brings the findings into a report you can review before responding.
Analyze an email with Blue Lantern Security
Web upload: .eml file, up to 4.5 MB. Account required. The free tier includes 30 daily runs shared across Email Analyzer, URL Threat Analyzer and Static Malware Analyzer. No credit card required. See current pricing.
Use the report to understand what needs attention and what to check next. A familiar sender name or a passing check alone cannot confirm a message is genuine. Verify unexpected requests for money, passwords or sensitive information through a contact method you already trust.
What does the Email Analyzer check?
The report combines several kinds of evidence. Read the finding behind a failed check before deciding what it means.
| Area | What to examine | What it cannot establish alone |
|---|---|---|
| Sender and headers | From and Reply-To differences, misleading display names and routing information | Different reply addresses can be legitimate; a familiar display name is not identity verification |
| Authentication | Reported SPF, DKIM and DMARC results | A pass does not establish honest intent; a failure can have configuration or forwarding causes |
| Message content | Urgency patterns, suspicious keywords, hidden content and scripts | Good grammar does not make a message genuine, and urgency can occur in legitimate mail |
| Links | Lookalike domains, shorteners, anchor-text mismatches and other available link findings | A link check does not confirm that a payment or password request is authorized |
| Domain context | Domain age and possible lookalike or sender/recipient-domain relationships | A new domain is not necessarily malicious; an old domain or account may be abused |
| Attachments | File types associated with executable content or macros | This check does not execute attachments or establish that their contents are harmless |
For deeper file inspection, select the optional Static Malware Analyzer check during web submission and review its separate result. Email Analyzer's attachment-type check does not execute the file. See the product documentation for the available checks.
How to check a suspicious email
- Pause the requested action. Do not reply with secrets, open an unexpected attachment, or follow a payment or login link while investigating. For work email, use your organization's reporting process.
- Preserve the original message. Export it as
.eml. In Gmail on a computer, open the message, choose More, then Download message. Other clients differ; use their original-message export feature. Renaming a.msgfile does not convert it. Gmail export instructions. - Check submission privacy. Email files can contain confidential text, recipients, attachments and personalized links. Use an approved service for the data involved. Keep an unchanged original: editing signed content can affect authentication analysis.
- Upload the file in Email Analyzer. Sign in, select the
.emlfile and submit it. Open the completed report from the app. A failed or incomplete job is not a clean result. - Read the evidence and verify the request. Compare the findings with what the sender wants you to do. Confirm unexpected payment changes, credential requests or sensitive-data requests using a known number or the organization's official app or website.
If your mobile mail app cannot export .eml, use the provider's desktop interface or your organization's reporting workflow. A screenshot may help explain a concern, but it does not preserve the original headers and attachments required by this web uploader.
How should I interpret the result?
| Result you encounter | Practical next step |
|---|---|
| Several failed checks | Inspect the named checks and evidence. Related formatting or delivery issues can trigger several failures; the count is not a probability of phishing |
| No detected warning signs | Still verify an unexpected or consequential request. A compromised legitimate account can send a convincing message |
| Missing evidence or an incomplete analysis | Keep the message unresolved. Check the input, retry an appropriate submission, or ask your security team |
| A request to send money or reveal credentials | Verify independently before acting, even if authentication and link checks pass |
Want to see how this works? Our report walkthrough explains an email marked Suspicious despite passing SPF and DKIM. For alternative workflows, compare the best tools to analyze a suspicious email.
What happens to uploaded email data?
Blue Lantern Security's policy distinguishes the original input from the resulting report: original email inputs are retained for up to one day; reports are retained for one week and are accessible only to the user who generated them. These periods do not describe all operational logs or account records. Review the Privacy Policy before submitting sensitive material and follow your organization's requirements.
Common questions
Can a phishing email pass SPF, DKIM and DMARC?
Yes. These mechanisms concern sending authorization, message signatures and domain alignment; they do not prove that the message's request is trustworthy. An attacker-controlled domain or a compromised account can send authenticated mail. Authentication failures also need context. Microsoft explains email authentication.
Can Blue Lantern Security check a screenshot, pasted text or .msg file?
The web uploader described here accepts .eml, up to 4.5 MB. It does not accept a screenshot, pasted email body or .msg file as a substitute. API and mailbox submission workflows have their own instructions in the product documentation.
Is checking the sender's email address enough?
No. An address can exist while its account is compromised, and a visible From address can be misleading. Address validation and breach-history lookups do not determine whether this particular message is genuine.
What if there is no link or attachment?
A message can still ask you to change bank details, buy gift cards or share sensitive information. Verify the request independently. A technical report cannot establish the sender's business authority.
Is it free, and can I automate it?
The web free tier includes the shared daily allowance described above. API access and monitoring require a paid seat, currently $15 per seat per month. Check pricing for current terms and API guidance for the workflow.
What if I already clicked or responded?
Stop interacting with the message and report it to your security team if it involves work. If you entered a password, secure the account through its official site; if you sent money, contact the payment provider promptly. Opening a link alone does not tell you whether an account or device was compromised. Follow the affected provider's recovery instructions. Microsoft's phishing guidance.
What if I only have a suspicious URL?
Use Check a Link. A URL investigation can reveal information about a destination, but it loses the surrounding email context.