Is this email really from your supplier?
Paste the email you received. It is read here in your browser, and you get an answer in plain language: what was seen, what it means, and what to do before you pay anything.
The message is read in your browser and never uploaded. Only the verdict is saved, and only if you create a shareable link — never the email itself, its subject, or who it was sent to.
Where do I find this?
- Gmail: open the message, click the three dots beside Reply, then “Show original”. Copy everything on that page.
- Outlook: open the message in its own window, then File → Properties. Copy the box marked “Internet headers”.
- Apple Mail: open the message, then View → Message → Raw Source. Copy everything.
What to do when a supplier asks to change bank details →
What “dkim=pass” really proves →
Questions
Is my email uploaded anywhere?
No. It is read inside your browser and never sent to this server. Two small lookups do leave your machine — the sending domain’s published key and its registration date — and both carry only a domain name, never any part of the message.
What is the difference between the three levels?
If you paste the full original message, the digital signature is checked here and the answer is ours. If you paste only the headers, all that can be read is the verdict your own mail server recorded on delivery — genuine and useful, but not our verification, and the headers are text like any other. If neither is present, only the sending domain’s public settings can be checked.
It says nothing suspicious was found. Can I pay the invoice?
Not on the strength of this page. The commonest invoice fraud is a genuine supplier whose mailbox has been broken into: the email really does come from their domain, every check passes, and the bank details are still the attacker’s. If this email asks you to change payment details, phone them on a number you already had.
Why does it want my supplier’s domain?
To compare it against the domain the message actually came from. A lookalike is only visible next to the real thing — supp1ier.com reads as supplier.com until the two are placed one above the other. Without it, only what the sending domain says about itself can be checked.
The signature could not be checked.
Some signatures deliberately cover only part of the message, some use an algorithm no longer considered sound, and some keys have been withdrawn. In each case the honest answer is that nothing was proved, which is what is reported — never a pass.