Message Loupe

About Message Loupe

Message Loupe is a free second-opinion tool for email. Drop a saved email, or paste its raw headers, and within a couple of seconds you get a plain-English verdict: no warning signs, caution, or likely fake. Each verdict explains the evidence and, when needed, the safest next action.

Why this exists

Most phishing-detection tools are aimed at security teams and cost five or six figures a year. The rest of us (freelancers, small businesses, people who handle their parents' bills, anyone who's ever stared at an email and wondered "is this really my bank?") get a spam folder and a hunch. Message Loupe is what happens when an analyst's triage engine is rebuilt for everyone else, with the jargon stripped out.

What Message Loupe answers (and what it doesn't)

Message Loupe answers a narrower question: what warning signs are present in the evidence it can inspect?A "No warning signs" result means it found no spoofing, sender-alignment, routing, or suspicious-link signals. It does not prove who controls the account or that a request is trustworthy. It also does not decide whether an email is wanted or relevant. Real cold outreach, marketing, and newsletters can pass these checks. Spam filtering is a different problem, handled (imperfectly) by your email provider.

What we're honest about

The verdict is advisory, not a guarantee. We can read the technical evidence in an email's headers: who really sent it, what server relayed it, whether the sender's domain authorizes that server. These checks can catch many common impersonation patterns, including fake banks, fake delivery services, lookalike domains, and hijacked login pages.

What we can't catch is when an attacker has already compromised a real account at a real vendor and is sending a real-looking request from that real address. Every technical signal passes, because from the email's perspective, nothing is wrong. That's why a message asking for money, banking details, credentials, identity documents, or a signed form can never receive "No warning signs" solely because its technical signals pass. It is at least Caution, with a verification step matched to the request: call a trusted number for money or banking changes, open the known site directly for credentials, and use an approved portal for documents or signed forms.

How it's built

The email analysis runs in your browser, with no upload or logging of your email. For non-webmail senders, the browser may make a domain-only MX lookup, and a same-site Cloudflare function may relay the sender domain to public RDAP services for its registration age. Message contents, headers, links, and verdicts are never sent. The engine powering the verdict began as an internal triage tool built for phishing analysts; you can read more in our methodology page.

Get in touch

Found a bug, have a question, or want to tell us about a phishing pattern we're missing? Email hello@messageloupe.com.