Portable forensic manifest

Email Evidence Manifest Builder

Hash a raw email and produce a portable JSON manifest of identity, authentication, transit, MIME and visible-link evidence without loading remote content.

email evidence hasheml sha256email forensic evidenceemail evidence manifest
Build a portable evidence manifest from a raw messageThe manifest hashes the supplied message text and summarizes identity, transit and MIME evidence. It does not contact links or remote resources.

What this analysis does

Paste raw .eml content or a complete header to create a SHA-256 evidence fingerprint, message and header hashes, identity snapshot, receiver-stamped authentication summary, transit metadata, content-type inventory, attachment filenames and visible URL hosts. The downloadable manifest documents the supplied evidence without claiming formal chain of custody.

How to use the result

Use real evidence

Paste the exact domain, header, message or configuration. The result is only as useful as the evidence supplied.

Review the findings

Mailybox separates observations from inferred causes so you can see what is known and what still needs verification.

Retest after changes

Email authentication and routing are stateful. Re-run the analysis after publishing a fix.

Interpretation matters

Email systems combine DNS, message-level evidence, provider policy and intermediate infrastructure. A single passing check is not proof that every message will deliver, and a single warning is not proof that a domain is misconfigured. Mailybox is designed to expose the evidence and the relationship between signals so the next action is clear.