drop eml files or mbox · extract all attachments · compute md5 sha1 sha256 hashes · identify file types by magic bytes · surface suspicious attachment types and hash-based threat intel lookup links · runs locally
email files
drop .eml or .mbox
or click
hashes computed locally · VT / MalwareBazaar links are lookup-only (no API calls)
drop .eml or .mbox files