Email Threat Analyzer
Detect phishing, malicious links, and suspicious sender patterns.
The Email Threat Analyzer performs security
analysis on email messages. Upload a .eml file and receive a threat report covering
header authentication, content analysis, and link scanning.
What It Analyzes
- Header Analysis — Validates SPF, DKIM, and DMARC authentication records to detect spoofed senders.
- Content Analysis — Scans for phishing keywords, social engineering patterns, and grammar anomalies.
- Link Analysis — Detects URL shorteners, lookalike domains, and known malicious URLs.
- Domain Analysis - Checks for typosquatting, recently registered domains, lookalike domains, and matching sender and recipient domains.
- Attachment Analysis - Only checks the type of attachment to see if it is a commonly used file type for embedded macros or malware. For more thorough static malicious file analysis please use our Static malware Analyzer in conjunction with this tool.
- Test Results Summary — Shows how many security checks passed or failed, giving you a clear picture of the email's safety.
File Requirements — File must be in .eml format (standard email export). Maximum file size: 4.5 MB. Most email clients let you export individual emails as .eml (File → Save As).
How to Use - UI
- Navigate to the Email Threat Analyzer page.
- Drag and drop a
.emlfile onto the upload area, or click "Select Email File" to browse. - Review the file name in the confirmation area, then click Submit for Analysis.
- (Optional) Tick Want to scan this email for malware too? to also submit the same
.emlto the Static Malware Analyzer in one step. When enabled, pick the malware checks to run. The estimated cost shown above the Submit button is the combined email + selected malware checks total. - Once processing completes, click View Report to see the full threat analysis, or find it on the Monitoring Hub. If you also requested malware analysis, that job appears as a separate entry under its tool.
How to Use - Phishing Mailbox
For inboxes or shared workflows where uploading every suspicious email through the UI isn't practical, Blue Lantern provides a forwarding mailbox. Anything sent in is analyzed automatically and the results show up on your Monitoring Hub.
- Sign in to the Email Threat Analyzer page. The mailbox addresses are shown under Alternative submission methods → Forward as attachment. They are only displayed to authenticated users, so they aren't visible to search engines or unauthenticated visitors.
- Pick the address for the account the report should file under:
- The personal address (
phishing@...) files the report under your personal account. - The account address (
<account-id>@..., shown on the tool page with your organization's real ID) files it under that shared account. Your account ID is also visible in the Account dropdown in the top navigation bar.
- Forward the suspicious message to that mailbox as a
.emlattachment. Most email clients let you do this from the More / ⋯ menu on the message (Gmail: "Forward as attachment", Outlook: "Forward as attachment"). Inline forwards rewrite the headers and will not analyze correctly. - The submission is charged to the account the address routes to, and reports appear in that account's Monitoring Hub, just like UI submissions.
Outlook caveat. Outlook rewrites portions of the original message headers when using Forward as Attachment, which can affect SPF, DKIM, and DMARC results in the report. If header authentication results are important for your investigation, save the original message as a .eml file (drag it from the message list to your desktop, or use File → Save As) and submit it through the UI or API instead of the forwarding mailbox.
Static malware analysis runs automatically for every mailbox submission. There is no UI option to disable it for this path. Pricing is the same as if you ran both tools yourself.
Who can forward
Submissions to the personal address are matched by sender: mail must come from the address you signed up with. For teams, use the account address instead; members of the organization can forward to it and the report files under the shared account.
How to Use - API
This API is designed to be plugged in to automation tools to allow for automatic email threat analysis. Please note, there is a limit of 600 requests in a 10 minute period for your account.
- Ensure you have provisioned an API key
- Leverage the /runs endpoint to submit your request. This will be a POST request using form data for the request data including the file. A sample curl command is provided below. Please note, if you want to check the cost of running the tool, you would include checkCost=true. This flag will make it so the analysis does not run and only the cost of the run is returned.
curl --location 'https://api.bluelanternsecurity.io/runs' \
--header 'Authorization: [YOUR API KEY]' \
--form 'tool="EMAILANALYZER"' \
--form 'checkCost="false"' \
--form 'file=@"[YOUR FILE PATH]"'
- After submission you will be provided a job ID that you will use in the subsequent call to fetch the results data. The jobID response will look as follows:
{
"message": "Requested Analysis Job Created",
"result": {
"jobId": "[JOB ID HERE]"
}
}
- The following curl request (after analysis is completed in approx. 30 seconds) will look as follows:
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [YOUR API KEY]' \
--data '{
"jobId":"[YOUR JOB ID]"
}'
- The results will look as follows:
{
"message": "results retrieved",
"result": {
"job_id": "[JOB ID]",
"filename": "[FILE NAME]",
"analyzed_at": "2026-03-17T15:51:51.002669+00:00",
"status": "Completed",
"Status": 200,
"Checks_failed": 6,
"Checks_total": 22,
"checks_results": [
{
"name": "From matches Reply-To",
"result": "Pass",
"type": "headers",
"description": "Checks if the 'From' address matches the 'Reply-To' address. Mismatches often indicate spoofing."
},
{
"name": "Private Domain Sender",
"result": "Pass",
"type": "headers",
"description": "Verifies the sender uses a private, organizational domain instead of a free provider."
},
{
"name": "Display Name Email Matches Sender Email",
"result": "Pass",
"type": "headers",
"description": "Checks if the display name contains a misleading email address that doesn't match the sender."
},
{
"name": "Matching Sender and Recipient Domain",
"result": "Fail",
"type": "headers",
"description": "Checks if the sender domain matches the recipient domain (Internal Email)."
},
{
"name": "No Sender Typosquatting",
"result": "Pass",
"type": "headers",
"description": "Verifies the sender domain is not mimicking the recipient domain (e.g. examp1e.com vs example.com)."
},
{
"name": "Fewer Than 6 Routing Hops",
"result": "Pass",
"type": "headers",
"description": "Checks for excessive server hops which might indicate relay abuse."
},
{
"name": "SPF Record Valid",
"result": "Pass",
"type": "headers",
"description": "SPF verifies that the sending server is authorized to send email on behalf of this domain."
},
{
"name": "DKIM Signature Valid",
"result": "Pass",
"type": "headers",
"description": "DKIM ensures the email content hasn't been tampered with during transit using cryptographic signatures."
},
{
"name": "DMARC Policy Valid",
"result": "Fail",
"type": "headers",
"description": "DMARC enforces policies for handling emails that fail authentication, protecting the domain reputation."
},
{
"name": "No Hops > 10 Minutes Or Backwards In Time",
"result": "Pass",
"type": "headers",
"description": "Checks if any hop in email routing took longer than 10 minutes or went backwards in time by greater than 1 second."
},
{
"name": "No Phishing Keywords",
"result": "Fail",
"type": "body",
"description": "Scans for common words and patterns typically found in spam and phishing attempts."
},
{
"name": "No Urgency Patterns",
"result": "Pass",
"type": "body",
"description": "Detects psychological triggers like 'Immediate Action' designed to make you act without thinking."
},
{
"name": "No Character Substitutions",
"result": "Pass",
"type": "body",
"description": "Checks for hidden characters or homoglyphs used to bypass spam filters."
},
{
"name": "No Active Scripts",
"result": "Pass",
"type": "body",
"description": "Detects dangerous executable scripts embedded in the email body."
},
{
"name": "Standard Spelling & Grammar",
"result": "Pass",
"type": "body",
"description": "Checks for poor spelling and grammar errors often found in mass-generated phishing emails."
},
{
"name": "No Hidden Content",
"result": "Fail",
"type": "body",
"description": "Detects invisible text or elements used to bypass security filters."
},
{
"name": "No Lookalike Domains",
"result": "Pass",
"type": "links",
"description": "Detects typosquatting domains that visually mimic legitimate brands to deceive users."
},
{
"name": "No Suspicious Shorteners",
"result": "Pass",
"type": "links",
"description": "Identifies generic URL shorteners often used to hide malicious destinations."
},
{
"name": "No Anchor Text Mismatches",
"result": "Fail",
"type": "links",
"description": "Verifies that the link text matches the actual URL, preventing deceptive redirection."
},
{
"name": "No Suspicious Hosting",
"result": "Fail",
"type": "links",
"description": "Checks if links point to abuse-prone free hosting services often used for phishing pages."
},
{
"name": "Domain Older Than 30 Days",
"result": "Pass",
"type": "domain",
"description": "Checks if the domain was registered recently (less than 30 days ago and is likely temporary)."
},
{
"name": "No Attachment Types That Could Be Executable",
"result": "Pass",
"type": "attachments",
"description": "Scans for executables, scripts, macros, and other dangerous file types."
}
],
"details": {
[EVIDENCE FROM ANALYSIS INCLUDED HERE]
}
}
}