Evidence formats
Phishing email and header analysis
Upload the suspicious message as .eml or paste its header block. PastePile reads the authentication results and the message structure and runs its phishing pack. Nothing in the pack touches the network: no link is fetched and no attachment is opened. Each case gets a timeline, findings that cite the exact records behind them, a list of what the evidence cannot establish, and hunts compiled to Defender KQL, Sentinel KQL, Splunk SPL, Elastic ES|QL and Sigma for the tools you already run.
What you can upload
- Full email messages (.eml)
- Pasted header blocks
What PastePile checks
- SPF, DKIM or DMARC failures, read from the receiving server's own Authentication-Results header rather than recomputed
- Reply-To addresses that differ from the sender
- Display names impersonating a person or organization
- Sender domains that look like a known domain
- Suspicious links (display text against target, punycode, redirectors, credential-looking parameters) and attachments (name, declared type, hash), judged from the message alone
Every finding cites the records behind it and states what it does not establish. Statistical signals are reported as rarity within your upload and never become findings. ATT&CK mappings describe what a behavior resembles, not proof that an adversary was present.
What it does not do
- No link detonation, attachment sandboxing or document detonation
- Reputation lookups are optional, shown to you before anything leaves, and treated as a third party's opinion
Try it
Open the synthetic Suspicious message case to see the timeline, findings, unknowns and report without an account. When you are ready, create an account and compare plans.