Authentication, decoded
SPF, DKIM, DMARC and ARC results in plain words — did this mail really come from where it claims?
Forward a suspicious email to Inspect. In about a minute, get a forensic report back: safe or not, and exactly why.
No sign-up. The report comes straight back to your inbox.
Exported a message as a file? Scan it right here — same forensic analysis, same EU residency, auto-deleted.
Drag & drop a .eml here, or
Max 25 MB · 3 scans per hour · analysed in the EU, then deleted
Send the questionable email to inspect@offseq.email from the inbox that received it.
Headers, sender identity, every link and every attachment — pulled apart and checked.
Links open in a throwaway browser and files in a sealed sandbox — isolated, then destroyed after the check.
A plain-language report lands in your inbox with a 0–100 risk score and the evidence behind it.
Every claim is backed by evidence you can read, with suspicious links defanged and never clickable. English or Latvian.
SPF, DKIM, DMARC and ARC results in plain words — did this mail really come from where it claims?
Display-name spoofing, look-alike domains, and reply-to / return-path mismatches that try to fool you.
Shorteners and redirect chains followed to the real destination, with a browser screenshot of the page — captured in isolation, up to 3 links per email.
Domain age, MX / DNS records and TLS posture of the sender and any destination — the boring details attackers get wrong.
Static analysis in a sealed sandbox: real file type vs. claimed, macros, embedded URLs, malware and YARA matches.
A deterministic 0–100 score, the top reasons, and a clear recommended action — not a vague “be careful”.
The email, screenshots and report are stored only in EU-jurisdiction Cloudflare R2 and D1 (region EEUR). No transfer outside the EU.
Links open in a throwaway Cloudflare Browser Run and files in a one-shot Sandbox, both destroyed after each check. Nothing dangerous ever runs on your device.
The risk score is computed deterministically from concrete signals. AI only writes the plain-language summary — it never decides whether something is malicious.
We keep the minimum, for the shortest time. There are no accounts and nothing to delete.
| What | Kept for |
|---|---|
| Original email & attachments | 72 hours |
| Browser screenshots | 7 days |
| The forensic report | 30 days |
Inspect judges one email at a time. The wider OffSeq Cybersecurity ecosystem watches your whole attack surface, continuously.
Live figures from real inspections, updated continuously.
Enough for anyone checking the occasional suspicious message. Need higher volume, integrations, or team access? Get in touch — OffSeq’s security services go far beyond a single inbox.