Email Header Analyzer
by @edgeiq-labs
Parses email headers to detect spoofing, phishing, SPF/DKIM/DMARC failures, routing anomalies, and provides forensic analysis of email authenticity.
clawhub install edgeiq-email-header-analyzer๐ About This Skill
Email Header Analyzer
Skill Name: email-header-analyzer
Version: 1.0.0
Category: Security / Email Forensics
Price: Lifetime: $39 / Optional Monthly: $7/mo (includes all Pro features permanently)
Author: EdgeIQ Labs
OpenClaw Compatible: Yes โ Python 3, pure stdlib, WSL + Linux
What It Does
Parses and analyzes email headers (RFC 5322) to detect spoofing, phishing indicators, SPF/DKIM/DMARC authentication failures, routing anomalies, and suspicious origin servers. Extracts forensic details from headers to determine if an email is legitimate or a spoof/impersonation attempt.
> โ ๏ธ Legal Notice: Only analyze emails you own or have explicit authorization to audit. Not for intercepting or analyzing others' communications without consent.
Features
Tier Comparison
| Feature | Free | Lifetime ($39) | Optional Monthly ($7/mo) | |---------|------|----------------|----------------------| | Full header parse | โ (5 emails) | โ (unlimited) | โ (unlimited) | | SPF/DKIM/DMARC check | โ | โ | โ | | From/Reply-To mismatch | โ | โ | โ | | Mail server IP reputation | โ | โ | โ | | Domain age lookup | โ | โ | โ | | Received path analysis | โ | โ | โ | | Attachment metadata | โ | โ | โ | | JSON export | โ | โ | โ |
Installation
cp -r /home/guy/.openclaw/workspace/apps/email-header-analyzer ~/.openclaw/skills/email-header-analyzer
Usage
Basic header scan (free tier)
python3 email_analyzer.py --header "Received: from mail.example.com..."
Paste raw headers from email (Pro)
EDGEIQ_EMAIL=your_email@gmail.com python3 email_analyzer.py \
--file /path/to/raw_headers.txt --pro
JSON report output
EDGEIQ_EMAIL=your_email@gmail.com python3 email_analyzer.py \
--header "$(pbpaste)" --bundle --output email-report.json
As OpenClaw Discord Command
In #edgeiq-support channel:
!emailheader Received: from server... Authentication-Results: spf=fail...
!emailheader --file /path/to/headers.txt --pro
Parameters
| Flag | Type | Default | Description |
|------|------|---------|-------------|
| --header | string | โ | Raw email headers (single line or multi-line) |
| --file | string | โ | Path to text file containing raw headers |
| --pro | flag | False | Enable Pro features |
| --bundle | flag | False | Enable Bundle features |
| --output | string | โ | Write JSON report to file |
Output Example
=== Email Header Analyzer ===
Analyzing headers for: phishing-suspicion@attacker.com [1m[91m๐ด SPF FAIL โ sender IP not authorized[0m
SPF Result: fail
From domain: company.com
Sender IP: 203.0.113.45 (not in SPFๅ
่ฎธๅ่กจ)
Recommendation: Block or mark as suspicious
[1m[93m๐ก DKIM: NONE (no signature found)[0m
Risk: Email has no cryptographic authentication
[1m[91m๐ด DMARC POLICY FAIL[0m
Policy: reject
Alignment: relaxed
Result: SPF fail + DKIM none = DMARC fail
[1m[93m๐ก FROM/REPLY-TO MISMATCH[0m
From: legitimate@company.com
Reply-To: refund@attacker-domain.com
Risk: Likely phishing or business email compromise
[1m[92mโ[0m Received path looks normal (3 hops)
Hop 1: mail.attacker.com [203.0.113.45]
Hop 2: relay.example.net [198.51.100.23]
Hop 3: mail.company.com [203.0.113.1]
Threat Level: HIGH โ Multiple authentication failures + Reply-To mismatch
Authentication Results Explained
| Result | Meaning | |--------|---------| | SPF pass | Sender IP is authorized by the domain's SPF record | | SPF fail | Sender IP is NOT authorized โ likely spoofing | | DKIM pass | Email digitally signed, signature valid | | DKIM fail | Signature tampered or invalid | | DMARC pass | Both SPF and DKIM aligned and passing | | DMARC fail | Alignment failed โ domain claimed but auth didn't match |
Pro Upgrade
Full forensic analysis + IP reputation + domain age + path analysis:
๐ Buy Lifetime โ $39 ๐ Subscribe Monthly โ $7/mo
Support
Open a ticket in #edgeiq-support or email gpalmieri21@gmail.com
๐ More from EdgeIQ Labs
edgeiqlabs.com โ Security tools, OSINT utilities, and micro-SaaS products for developers and security professionals.
๐ก Examples
Basic header scan (free tier)
python3 email_analyzer.py --header "Received: from mail.example.com..."
Paste raw headers from email (Pro)
EDGEIQ_EMAIL=your_email@gmail.com python3 email_analyzer.py \
--file /path/to/raw_headers.txt --pro
JSON report output
EDGEIQ_EMAIL=your_email@gmail.com python3 email_analyzer.py \
--header "$(pbpaste)" --bundle --output email-report.json
As OpenClaw Discord Command
In #edgeiq-support channel:
!emailheader Received: from server... Authentication-Results: spf=fail...
!emailheader --file /path/to/headers.txt --pro