With EmailAnalyzer you can able to analyze your suspicious emails. You can extract headers, links and hashes from the .eml file
usage: email-analyzer.py [-h] [--version] -f FILENAME [-H] [-d] [-l] [-a] [-A] [-D] [-i] [-o OUTPUT]
options:
-h, --help show this help message and exit
--version Show program version and exit
-f, --filename FILENAME
Name of the EML file
-H, --headers To get the Headers of the Email
-d, --digests To get the Digests of the Email
-l, --links To get the Links from the Email
-a, --attachments To get the Attachments from the Email
-A, --authentication To get the Authentication Results of the Email (SPF, DKIM, DMARC)
-D, --defang Defang URLs in Links output (hxxps://, [.] notation)
-i, --investigate Activate if you want an investigation
-o OUTPUT, --output OUTPUT
Name of the Output file (Only HTML or JSON format supported)
This command will get you Headers, Links, Attachments, and Digests with Investigations:
python3 email-analyzer.py -f <eml file>
If you want to extract the outputs to a file you can use this commands:
python3 email-analyzer.py -f <eml file> -o report.html
or
python3 email-analyzer.py -f <eml file> -o report.json
Only supported JSON and HTML formats currently.
python3 email-analyzer.py -f <eml file> --headers
or
python3 email-analyzer.py -f <eml file> -H
βββ βββββββββββ ββββββ βββββββ βββββββββββββββ ββββββββ
βββ βββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββ βββββββββββ βββββββββ ββββββββββββββββ
ββββββββββββββ βββββββββββ βββββββββ ββββββββββββββββ
βββ ββββββββββββββ ββββββββββββββββββββββ βββββββββββ
βββ ββββββββββββββ ββββββββββ βββββββββββ βββββββββββ
_________________________________________________________
[received]
from TEST.TEST.PROD.OUTLOOK.COM (2603:10a6:20b:4f2::13)
by TEST.TEST.PROD.OUTLOOK.COM with HTTPS; Fri, 25 Nov 2022
12:36:39 +0000
_________________________________________________________
_________________________________________________________
[content-type]
multipart/alternative; boundary=335b23d5689bd75ab002f9c46a6e8023c265d60dd923308dcc7eb7a2cf25
_________________________________________________________
_________________________________________________________
[date]
Fri, 25 Nov 2022 12:36:36 +0000 (UTC)
_________________________________________________________
_________________________________________________________
[subject]
How to use EmailAnalyzer
_________________________________________________________
_________________________________________________________
[reply-to]
info123@gmail.com
_________________________________________________________
_________________________________________________________
[from]
"Admin"<info@officialmail.com>
_________________________________________________________
_________________________________________________________
[to]
me
_________________________________________________________
_________________________________________________________
[x-sender-ip]
127.0.0.1
_________________________________________________________
RFC 2047 encoded headers (e.g.
=?UTF-8?B?...?=) are automatically decoded and displayed as readable text.
python3 email-analyzer.py -f <eml file> --headers --investigate
or
python3 email-analyzer.py -f <eml file> -Hi
ββββββ ββββ βββ ββββββ βββ βββ ββββββββββββββββββββββ
βββββββββββββ ββββββββββββββ ββββ βββββββββββββββββββββββ
ββββββββββββββ ββββββββββββββ βββββββ βββββββββββββββββββ
βββββββββββββββββββββββββββββ βββββ βββββββββββββββββββ
βββ ββββββ βββββββββ ββββββββββββββ βββββββββββββββββββ
βββ ββββββ ββββββββ ββββββββββββββ βββββββββββββββββββ
_________________________________________________________
[X-Sender-IP]
Virustotal:
https://www.virustotal.com/gui/search/127.0.0.1
Abuseipdb:
https://www.abuseipdb.com/check/127.0.0.1
_________________________________________________________
_________________________________________________________
[Spoof Check]
Reply-To:
info123@gmail.com
From:
info@officialmail.com
Conclusion:
Reply Address and From Address is NOT Same. This mail may be SPOOFED.
_________________________________________________________
Investigation also extracts public IP addresses from
Receivedheaders and generates VirusTotal and AbuseIPDB lookup links for each one.
The -i / --investigate flag enables all of the following checks when used with -H:
| Check | What it detects |
|---|---|
| X-Sender-IP | Generates VirusTotal and AbuseIPDB lookup links for the sending IP |
| X-Originating-IP | Same lookup links for the X-Originating-IP header when present |
| Received IPs | Extracts all public IPs from Received headers and generates lookup links |
| Spoof Check | Flags when Reply-To and From addresses differ |
| Display Name Check | Flags when the From display name contains a domain that doesn't match the sending domain (e.g. display name "paypal.com" sent from attacker@gmail.com) |
| Reply-To Domain Check | Flags when the Reply-To domain differs from the From domain β replies would be redirected to a different domain |
| Suspicious Headers | Flags missing Message-ID, missing MIME-Version, dates far in the future or past (>2 days / >30 days), and known bulk-sender X-Mailer values (PHPMailer, The Bat, libwww-perl) |
python3 email-analyzer.py -f <eml file> --authentication
or
python3 email-analyzer.py -f <eml file> -A
Parses Authentication-Results and Received-SPF headers to extract SPF, DKIM, and DMARC verdicts.
ββββββ βββ βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββ ββββββ ββββββββββββ βββββββ ββββ βββ
βββββββββββ βββββββββββββββ ββββββββββββββββ βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ βββ
βββββββββββ βββ βββ ββββββββββββββ ββββββ βββ βββ ββββββ ββββββββ βββ ββββββ βββββββββ βββ
βββββββββββ βββ βββ ββββββββββββββ ββββββββββ βββ ββββββ ββββββββ βββ ββββββ βββββββββββββ
βββ ββββββββββββ βββ βββ ββββββββββββββ ββββββ βββ ββββββββββββββ βββ βββ βββββββββββββββ ββββββ
βββ βββ βββββββ βββ βββ ββββββββββββββ βββββ βββ βββ ββββββββββ βββ βββ βββ βββββββ βββ βββββ
_________________________________________________________
[SPF]
pass
_________________________________________________________
_________________________________________________________
[DKIM]
pass
_________________________________________________________
_________________________________________________________
[DMARC]
pass
_________________________________________________________
python3 email-analyzer.py -f <eml file> --digests
or
python3 email-analyzer.py -f <eml file> -d
βββββββ βββ βββββββ βββββββββββββββββββββββββββββββββ
βββββββββββββββββββ βββββββββββββββββββββββββββββββββ
βββ βββββββββ ββββββββββ ββββββββ βββ ββββββββ
βββ βββββββββ βββββββββ ββββββββ βββ ββββββββ
ββββββββββββββββββββββββββββββββββββ βββ ββββββββ
βββββββ βββ βββββββ ββββββββββββββββ βββ ββββββββ
_________________________________________________________
[File MD5]
81dc9bdb52d04dc20036dbd8313ed055
_________________________________________________________
_________________________________________________________
[File SHA1]
7110eda4d09e062aa5e4a390b0a572ac0d2c0220
_________________________________________________________
_________________________________________________________
[File SHA256]
03ac674216f3e15c761ee1a5e255f067953623c8b388b4459e13f978d7c846f4
_________________________________________________________
_________________________________________________________
[Content MD5]
827ccb0eea8a706c4c34a16891f84e7b
_________________________________________________________
_________________________________________________________
[Content SHA1]
8cb2237d0679ca88db6464eac60da96345513964
_________________________________________________________
_________________________________________________________
[Content SHA256]
5994471abb01112afcc18159f6cc74b4f511b99806da59b3caf5a9c173cacfc5
_________________________________________________________
python3 email-analyzer.py -f <eml file> --digests --investigate
or
python3 email-analyzer.py -f <eml file> -di
ββββββ ββββ βββ ββββββ βββ βββ ββββββββββββββββββββββ
βββββββββββββ ββββββββββββββ ββββ βββββββββββββββββββββββ
ββββββββββββββ ββββββββββββββ βββββββ βββββββββββββββββββ
βββββββββββββββββββββββββββββ βββββ βββββββββββββββββββ
βββ ββββββ βββββββββ ββββββββββββββ βββββββββββββββββββ
βββ ββββββ ββββββββ ββββββββββββββ βββββββββββββββββββ
_________________________________________________________
[File MD5]
Virustotal:
https://www.virustotal.com/gui/search/81dc9bdb52d04dc20036dbd8313ed055
_________________________________________________________
_________________________________________________________
[File SHA1]
Virustotal:
https://www.virustotal.com/gui/search/7110eda4d09e062aa5e4a390b0a572ac0d2c0220
_________________________________________________________
_________________________________________________________
[File SHA256]
Virustotal:
https://www.virustotal.com/gui/search/03ac674216f3e15c761ee1a5e255f067953623c8b388b4459e13f978d7c846f4
_________________________________________________________
_________________________________________________________
[Content MD5]
Virustotal:
https://www.virustotal.com/gui/search/827ccb0eea8a706c4c34a16891f84e7b
_________________________________________________________
_________________________________________________________
[Content SHA1]
Virustotal:
https://www.virustotal.com/gui/search/8cb2237d0679ca88db6464eac60da96345513964
_________________________________________________________
_________________________________________________________
[Content SHA256]
Virustotal:
https://www.virustotal.com/gui/search/5994471abb01112afcc18159f6cc74b4f511b99806da59b3caf5a9c173cacfc5
_________________________________________________________
python3 email-analyzer.py -f <eml file> --links
or
python3 email-analyzer.py -f <eml file> -l
βββ βββββββ ββββββ βββββββββββ
βββ ββββββββ ββββββ ββββββββββββ
βββ βββββββββ ββββββββββ ββββββββ
βββ ββββββββββββββββββββ ββββββββ
ββββββββββββββ βββββββββ βββββββββββ
ββββββββββββββ ββββββββ βββββββββββ
[1]->https://example.com
[2]->https://testlinks.com/campaing/123124
Links are extracted from both HTML (
hrefattributes) and plain-text parts of the email. Bare URLs in plain-text bodies (e.g.https://example.com) are also captured and deduplicated.
Add -D / --defang to convert URLs to defanged format (hxxps://, [.] for domain dots). Safe to share in reports without creating clickable links.
python3 email-analyzer.py -f <eml file> --links --defang
or
python3 email-analyzer.py -f <eml file> -lD
[1]->hxxps://example[.]com
[2]->hxxps://testlinks[.]com/campaing/123124
python3 email-analyzer.py -f <eml file> --links --investigate
or
python3 email-analyzer.py -f <eml file> --li
ββββββ ββββ βββ ββββββ βββ βββ ββββββββββββββββββββββ
βββββββββββββ ββββββββββββββ ββββ βββββββββββββββββββββββ
ββββββββββββββ ββββββββββββββ βββββββ βββββββββββββββββββ
βββββββββββββββββββββββββββββ βββββ βββββββββββββββββββ
βββ ββββββ βββββββββ ββββββββββββββ βββββββββββββββββββ
βββ ββββββ ββββββββ ββββββββββββββ βββββββββββββββββββ
_________________________________________________________
[1]
VirusTotal:
https://www.virustotal.com/gui/search/example.com
UrlScan:
https://urlscan.io/search/#example.com
_________________________________________________________
_________________________________________________________
[2]
VirusTotal:
https://www.virustotal.com/gui/search/testlinks.com/campaing/123124
UrlScan:
https://urlscan.io/search/#testlinks.com/campaing/123124
_________________________________________________________
python3 email-analyzer.py -f <eml file> --attachments
or
python3 email-analyzer.py -f <eml file> -a
ββββββ ββββββββββββββββββ ββββββ ββββββββββ βββββββββββ
βββββββββββββββββββββββββββββββββββββββββββββ βββββββββββ
ββββββββ βββ βββ βββββββββββ ββββββββββββββββ
ββββββββ βββ βββ βββββββββββ ββββββββββββββββ
βββ βββ βββ βββ βββ ββββββββββββββ βββββββββββ
βββ βββ βββ βββ βββ βββ ββββββββββ βββββββββββ
[1] example.pdf (application/pdf)
_________________________________________________________
[2] malicious.pdf (application/octet-stream)
_________________________________________________________
The MIME type is shown alongside the filename, allowing you to detect files whose extension does not match their actual content type (e.g. a
application/octet-stream).
python3 email-analyzer.py -f <eml file> --attachments --investigate
or
python3 email-analyzer.py -f <eml file> -ai
ββββββ ββββ βββ ββββββ βββ βββ ββββββββββββββββββββββ
βββββββββββββ ββββββββββββββ ββββ βββββββββββββββββββββββ
ββββββββββββββ ββββββββββββββ βββββββ βββββββββββββββββββ
βββββββββββββββββββββββββββββ βββββ βββββββββββββββββββ
βββ ββββββ βββββββββ ββββββββββββββ βββββββββββββββββββ
βββ ββββββ ββββββββ ββββββββββββββ βββββββββββββββββββ
_________________________________________________________
- example.pdf
Virustotal:
[Name Search]->https://www.virustotal.com/gui/search/example.pdf
[MD5]->https://www.virustotal.com/gui/search/81dc9bdb52d04dc20036dbd8313ed055
[SHA1]->https://www.virustotal.com/gui/search/7110eda4d09e062aa5e4a390b0a572ac0d2c0220
[SHA256]->https://www.virustotal.com/gui/search/03ac674216f3e15c761ee1a5e255f067953623c8b388b4459e13f978d7c846f4
_________________________________________________________
_________________________________________________________
- malicious.pdf
Virustotal:
[Name Search]->https://www.virustotal.com/gui/search/malicious.pdf
[MD5]->https://www.virustotal.com/gui/search/827ccb0eea8a706c4c34a16891f84e7b
[SHA1]->https://www.virustotal.com/gui/search/8cb2237d0679ca88db6464eac60da96345513964
[SHA256]->https://www.virustotal.com/gui/search/5994471abb01112afcc18159f6cc74b4f511b99806da59b3caf5a9c173cacfc5
_________________________________________________________
_________________________________________________________
- Duplicate Warning
[03ac674216f3e15c761ee1a5e255f067953623c8b388b4459e13f978d7c846f4]
example.pdf
malicious.pdf
_________________________________________________________
When two or more attachments share the same SHA256 hash, a Duplicate Warning is added to the investigation output listing the shared hash and the filenames involved.
Generate a self-contained HTML report with Bootstrap 5 styling:
python3 email-analyzer.py -f <eml file> -o report.html
The HTML report includes:
- Threat Summary β email overview (From, To, Subject, Date, link/attachment counts), threat level badge (LOW / MEDIUM / HIGH), and Bootstrap alert cards for each triggered investigation check
- Sticky navbar β always visible while scrolling, with jump links to each section
- Copy-to-clipboard buttons β next to every hash value and URL for quick threat-intel lookups
- Clickable investigation links β all VirusTotal, AbuseIPDB, and URLscan entries are rendered as anchor tags
- Merged tables β Links, Attachments, and Digests each show data and scan links in a single unified table
python3 email-analyzer.py --version
The test suite uses pytest. Install it before running tests:
pip install pytest
Run all tests from the project root:
python3 -m pytest tests/ -v
Run a specific test file:
python3 -m pytest tests/test_headers.py -v
python3 -m pytest tests/test_links.py -v
python3 -m pytest tests/test_digests.py -v
python3 -m pytest tests/test_attachments.py -v
python3 -m pytest tests/test_auth_results.py -v
python3 -m pytest tests/test_defang.py -v
python3 -m pytest tests/test_duplicate_attachments.py -v
python3 -m pytest tests/test_cli.py -v
tests/
βββ fixtures/ # Sample .eml files used by tests
β βββ basic.eml
β βββ spoofed.eml
β βββ not_spoofed.eml
β βββ display_name_only.eml
β βββ quoted_printable.eml
β βββ no_links.eml
β βββ binary_attachment.eml
β βββ multi_attachment.eml
β βββ image_attachment.eml
β βββ no_attachment.eml
β βββ no_filename_attachment.eml
β βββ multipart_alternative.eml
β βββ duplicate_attachments.eml
β βββ rfc2047_encoded.eml
β βββ rfc2047_qp_encoded.eml
β βββ rfc2047_mixed.eml
β βββ received_public_ips.eml
β βββ received_mixed_ips.eml
β βββ auth_pass_all.eml
β βββ auth_fail_spf_dkim.eml
β βββ auth_softfail_spf.eml
β βββ auth_received_spf_only.eml
β βββ auth_no_headers.eml
β βββ phishing_displayname.eml
β βββ legitimate_displayname.eml
β βββ suspicious_no_message_id.eml
β βββ suspicious_future_date.eml
β βββ suspicious_old_date.eml
β βββ suspicious_xmailer.eml
β βββ clean_headers.eml
β βββ originating_ip.eml
β βββ replyto_diff_domain.eml
β βββ replyto_same_domain.eml
βββ conftest.py # Shared fixtures and module loader
βββ test_headers.py # Tests for get_headers()
βββ test_links.py # Tests for get_links()
βββ test_digests.py # Tests for get_digests()
βββ test_attachments.py # Tests for get_attachments()
βββ test_attachment_mime.py # Tests for MIME type in attachment output
βββ test_duplicate_attachments.py # Tests for duplicate attachment detection
βββ test_rfc2047.py # Tests for RFC 2047 encoded header decoding
βββ test_received_ips.py # Tests for Received header IP extraction
βββ test_auth_results.py # Tests for SPF/DKIM/DMARC parsing
βββ test_defang.py # Tests for defanged URL output
βββ test_plaintext_links.py # Tests for plain-text URL extraction
βββ test_display_name.py # Tests for display name spoofing detection
βββ test_suspicious_headers.py # Tests for suspicious header pattern detection
βββ test_originating_ip.py # Tests for X-Originating-IP investigation
βββ test_replyto_domain.py # Tests for Reply-To domain check
βββ test_html_generator.py # Tests for HTML report generation and XSS escaping
βββ test_cli.py # Tests for CLI argument validation
βββ test_encoding.py # Tests for non-UTF-8 email encoding handling