Shine a light on suspicious email

See the risk before you act.

Free built-in checks. No account required. No scan history.

app.maillume.io

Email analysis

Check a suspicious email

Subject

Invoice overdue: action required

Sender

billing@vendor-check.example

Email content

We could not process your latest payment. Review the invoice immediately to avoid account suspension.https://vendor-check.example/review
Analyze email

Risk score

78

High
Creates urgency around an account problem.
Link destination does not match the claimed sender.
Verify through a known contact channel before acting.

Automated risk assessment. This result is not a guarantee.

  1. 01

    Choose the email in front of you.

    Open a message yourself. Maillume never reads a mailbox in the background.

  2. 02

    Paste text, scan a screenshot, or open an .eml file.

    Source files stay in your browser; only the normalized text needed for this check is processed once.

  3. 03

    Read the action, then verify independently.

    Use a known contact channel before you click, reply, or approve anything.

A clearer risk assessment

Suspicious emails rarely look suspicious everywhere.

Maillume brings the small clues together, explains them in plain language, and helps you choose a safer next step. The score supports your decision; it never guarantees that a message is safe or malicious.

01

Three input options

Check the message in front of you.

Paste the text, read a screenshot, or open an exported .eml file. Source files stay in your browser; normalized text is sent once for the assessment and is not retained.

02

Explainable assessment

See the evidence behind the score.

Maillume shows the signals it found, how they affected the risk score, which links were detected, and what to do next.

03

No scan history

Processed for this check, not kept as history.

Email text, sender details, links, screenshots, .eml files, and completed results are not written to application storage.

What leaves the browser

Your file stays local. The analysis text is processed once.

Screenshot OCR and .eml parsing happen in your browser. Only the normalized text needed for this assessment is sent to the selected Maillume deployment, and it is discarded when the request ends.

01

Your browser

Parses files and extracts readable text.

02

Maillume analysis

Weighs risk signals and returns an explainable assessment.

03

Request ends

Email content and results are not written to application storage.

Hosted by us

Check an email without setting anything up.

The hosted scanner uses built-in checks based on visible warning signs. Anonymous scans need no account; an optional account lets you manage API keys without creating scan history.

Open Maillume

Hosted by you

Keep the complete scanner under your control.

Deploy the AGPL application on your own infrastructure. Keep the predictable heuristic mode, or connect an AI provider with a server-side key you own.

Explore self-hosting

Incident notes · February 2026

When phishing moves from email to phone.

NOS reported that the Odido attack combined credential phishing, impersonation of internal IT, and fraudulent login approval. The case shows why email checks are only one layer of a safer verification process.

Read the incident notes

Open development

Read the code, challenge the scoring, and help make suspicious email easier to understand.

Follow on GitHub
Maillume — Explainable email risk checks