Header forensics
Decode routing, authentication, and sender anomalies without digging through raw headers.
Explore capability →Investigate phishing, spam, and impersonation with an AI copilot that turns complex email evidence into a clear, defensible verdict.
High-confidence impersonation attempt
This email impersonates Microsoft to harvest credentials. The sending domain replaces the letter “o” with a zero, fails DMARC authentication, and directs the recipient to a newly registered external login page.
Give every analyst the context to make faster, more consistent decisions—without losing the technical detail behind the verdict.
Decode routing, authentication, and sender anomalies without digging through raw headers.
Explore capability →Unwrap redirects, flag deceptive domains, and surface risky destinations in seconds.
Explore capability →Catch display-name spoofing, lookalike domains, and subtle reply-to manipulation.
Explore capability →Turn technical evidence into a concise verdict with reasoning and next actions.
Explore capability →Collect domains, IPs, URLs, hashes, and identities into one exportable evidence set.
Explore capability →Preserve findings, analyst notes, and an audit-friendly timeline for every investigation.
Explore capability →Forward an email, upload an EML file, or connect your mailbox workflow.
Correlate authentication, infrastructure, content, URLs, and sender identity.
Receive an AI-assisted verdict with evidence, confidence, and recommended actions.
Export findings, enrich your case, and move indicators into the tools you trust.
TraceMail is designed around controlled access, transparent retention, and data-minimizing investigation workflows.
Simple launch options for teams evaluating a new email-forensics workflow.
This website presents the planned product experience. Live analysis, accuracy, integrations, and availability must be confirmed before production launch.
The proposed workflow supports forwarded messages and EML uploads, with mailbox ingestion planned subject to product implementation.
No. The experience is designed to explain evidence and assist analysts. Human review remains central to consequential security decisions.
API, SIEM, SOAR, ticketing, Microsoft 365, and Google Workspace integrations are proposed capabilities and will be labeled by actual availability.
Join the early-access list for product updates and a guided walkthrough of the proposed investigation experience.
Your request is sent to the WordPress administrator email.