Analyze a suspicious email
Noetis explains what a suspicious message really is and what to do next — in plain English. It's analyzed privately and the raw copy is deleted afterward. Works with Gmail, Microsoft 365, Apple Mail, or any provider.
The easy way — forward it as an attachment
No file to export: use your mail app's “Forward as attachment” option to send the suspicious email to your private address, and we'll email the report straight back. A normal “Forward” won't work — it strips the evidence we analyze — so the steps below show exactly where the right button hides in each mail app.
Or upload the file instead
If you'd rather save the original message and drop it here, that works too — same analysis, same report. Best on a computer.
Before you send it — tips for the best result
- Send the original message — forward it as an attachment, or upload the saved
.eml/.msgfile. That is the best evidence. - Screenshots are not enough — an image can't be analyzed for sender, headers, or links.
- Copied/pasted text is not enough — the hidden technical headers are what we need.
- A plain forward may have limited evidence — a normal "Forward" can strip the original sender's headers. Forwarding as an attachment (or uploading the original) keeps them.
- Do not click links or open attachments in the suspicious email before (or after) submitting it.
Not sure which method fits your email, or submitting from a phone? See how to submit a suspicious email for every method and its limits.
How to export the original message for upload (Gmail, Outlook, Apple Mail, and more)
Works the same whoever hosts your email — Google Workspace, Microsoft 365, GoDaddy, your web host, or a plain account. Steps change as these apps update; if something looks different, look for a Download, Save as, or Show original option. On a phone, or if this feels fiddly, just forward it as an attachment instead — no exporting needed.
Gmail / Google Workspace
- Open the suspicious email.
- Click the ⋮ (More) menu next to the Reply arrow.
- Choose Download message (saves an
.emlfile). - Upload that
.emlfile here.
Outlook / Microsoft 365 (web)
- Open the suspicious email.
- Click the ⋯ (More actions) menu at the top right of the message.
- Choose Download (saves an
.emlfile). - Upload that
.emlfile here.
Outlook (desktop app)
- Open (or single-click) the suspicious email.
- Drag it from the list straight onto your desktop, or choose
File → Save As. - Save as type Outlook Message Format (
.msg). - Upload that saved
.msgfile here.
Apple Mail (Mac)
- Click the suspicious email in the list.
- Drag it straight onto your desktop, or choose
File → Save Asand pick Raw Message Source. - You'll get an
.emlfile. - Upload that
.emlfile here.
iPhone / iPad (and most phone mail apps)
- Honestly: phone mail apps (Apple Mail, the Gmail app, Outlook mobile) can't forward as an attachment or save the original file — a regular phone “Forward” strips the evidence we need.
- The reliable path is a computer: open the same mailbox in a desktop browser or mail app and use any method on this page.
- No computer handy? Leave the email unread — it can wait safely as long as you don't tap its links or attachments.
Yahoo, AOL, or other webmail
- Open the suspicious email.
- Look in the ⋯ / More menu for Download, Save as, or View raw message.
- Save the
.emlfile (or, if there's no download, forward it as an attachment). - Upload that file here.
Received the email as someone else's forward? Ask them to send you the original as an attachment, then export that attached message using the steps above.