MAILTRACEEMAIL FORENSICS / THUGS(red)
THREAT HUNTING STARTS AT THE SOURCE

EVERY HEADER.
LEAVES A TRACE.

Unpack the message. Follow the route. Connect the evidence.
A forensic workspace for everything hiding in your inbox.

EML + RAW HEADERSTRANSPORT INTELLIGENCEBUILT FOR ANALYSTS
An email envelope on a forensic analysis platform, connected by neon network routes FOLLOW THE SIGNAL / FIND THE STORY
01

Drop the evidence.

Raw headers or a complete email. The investigation starts here.

MAX 5 MiB
⌘   PASTE EMAIL SOURCE0 bytes
HTML NEVER EXECUTED

External checks share extracted indicators with their providers. AI runs only when requested.

PRIVATE WORKSPACE · INVITE-ONLY ACCESS
⌁

Follow every hop

Reconstruct SMTP transport, relay delays, TLS evidence and network ownership.

◎

Read between the headers

Inspect authentication claims, identity mismatches and the anatomy of a message.

⌗

Extract the evidence

Carve attachments, calculate hashes and correlate indicators with threat intelligence.

◈

Share the view, safely

Mask sensitive evidence for screenshots and export a deliberately redacted report.

FROM ORIGIN TO INBOX

A route tells a story.

ILLUSTRATIVE TRANSPORT
01 / ORIGINSenderMessage created
ESMTPS ↗
02 / RELAYMail gatewayTLS reported
SMTP ↗
03 / DELIVERYRecipient MXEvidence preserved

Actual routes are reconstructed from supplied Received headers. A reported hop or TLS claim is evidence to assess, not independent verification.

KNOW WHAT THE EVIDENCE CAN SAY

Investigate with context.

Headers can be forged. A passing authentication claim can be copied. An unknown hash can still be malicious. MAILTRACE keeps observations, external intelligence and interpretation distinct.

What is analyzed?

SMTP hops, claimed TLS and authentication, sender identities, dates, MIME structure, HTML link mismatches, remote image candidates, suspicious attachment types, file hashes and extracted IP, domain, email and URL indicators. SPF/DMARC are not re-evaluated; DKIM/ARC signatures are not cryptographically verified.

What happens to submitted evidence?

Original source bytes, decoded attachments, parsed records, indicators, submission IP, analysis and lookup responses are retained indefinitely in the database, encrypted by the application. Only submit material you are authorized to retain here. Reports belong to your account; server administrators can access stored evidence. There is no automatic deletion or public report directory.

Which external services receive data?

When enrichment is enabled, Geo/ASN use local MaxMind GeoLite2 databases. Public IPs go to RIPEstat for registry data; ipwho.is is a fallback if local databases are unavailable; domains go to RDAP registries and DNS queries use the server resolver. Configured Spamhaus, AbuseIPDB, VirusTotal and PhishTank receive applicable indicators. VirusTotal receives hashes and URL identifiers, never attachment bytes. Up to eight indicators per type are enriched on each run. DNS is cached for two days; registry and geo for seven days; VirusTotal for three days; other reputation for one day. Cache timestamps are preserved. Lookups describe current or previously recorded reputation, not safety.

What does screenshot privacy protect?

It replaces names, addresses, IPs, hostnames, subjects, filenames, identifiers and other evidence values in the interface. Free-text source, body, lookup payloads and AI prose are hidden. It does not alter stored data or anonymize network requests. Raw exports and attachment downloads are disabled while privacy is on.

How does AI analysis work?

AI is off by default. You can request a local Ollama or LM Studio assessment, or a configured cloud provider. A bounded selection of parsed findings, headers and metadata is sent to that provider. No attachments or original message bodies are sent. AI text is an interpretation to verify; it is never used as an automated verdict.

TRUSTED ANALYST ACCESS

Enter the workspace.

Sign in with an account issued by your administrator.

No public registration. Session cookies are used only to keep you signed in and protect requests.

WORKSPACE SETTINGS

Your workspace.