Follow every hop
Reconstruct SMTP transport, relay delays, TLS evidence and network ownership.
Unpack the message. Follow the route. Connect the evidence.
A forensic workspace for everything hiding in your inbox.
Raw headers or a complete email. The investigation starts here.
Reconstruct SMTP transport, relay delays, TLS evidence and network ownership.
Inspect authentication claims, identity mismatches and the anatomy of a message.
Carve attachments, calculate hashes and correlate indicators with threat intelligence.
Mask sensitive evidence for screenshots and export a deliberately redacted report.
Actual routes are reconstructed from supplied Received headers. A reported hop or TLS claim is evidence to assess, not independent verification.
Headers can be forged. A passing authentication claim can be copied. An unknown hash can still be malicious. MAILTRACE keeps observations, external intelligence and interpretation distinct.
SMTP hops, claimed TLS and authentication, sender identities, dates, MIME structure, HTML link mismatches, remote image candidates, suspicious attachment types, file hashes and extracted IP, domain, email and URL indicators. SPF/DMARC are not re-evaluated; DKIM/ARC signatures are not cryptographically verified.
Original source bytes, decoded attachments, parsed records, indicators, submission IP, analysis and lookup responses are retained indefinitely in the database, encrypted by the application. Only submit material you are authorized to retain here. Reports belong to your account; server administrators can access stored evidence. There is no automatic deletion or public report directory.
When enrichment is enabled, Geo/ASN use local MaxMind GeoLite2 databases. Public IPs go to RIPEstat for registry data; ipwho.is is a fallback if local databases are unavailable; domains go to RDAP registries and DNS queries use the server resolver. Configured Spamhaus, AbuseIPDB, VirusTotal and PhishTank receive applicable indicators. VirusTotal receives hashes and URL identifiers, never attachment bytes. Up to eight indicators per type are enriched on each run. DNS is cached for two days; registry and geo for seven days; VirusTotal for three days; other reputation for one day. Cache timestamps are preserved. Lookups describe current or previously recorded reputation, not safety.
It replaces names, addresses, IPs, hostnames, subjects, filenames, identifiers and other evidence values in the interface. Free-text source, body, lookup payloads and AI prose are hidden. It does not alter stored data or anonymize network requests. Raw exports and attachment downloads are disabled while privacy is on.
AI is off by default. You can request a local Ollama or LM Studio assessment, or a configured cloud provider. A bounded selection of parsed findings, headers and metadata is sent to that provider. No attachments or original message bodies are sent. AI text is an interpretation to verify; it is never used as an automated verdict.