Email investigation workspace

Turn inbox doubt into clear evidence.

ThreatTrace brings mailbox connections, deterministic forensics, reputation intelligence, and AI-assisted context into one calm workflow for suspicious email.

GMAIL · OUTLOOK · EML / PRIVATE SESSION WORKSPACE

LIVE INVESTIGATION / TT-0428EVIDENCE READY
MESSAGE SIGNALS

Account security notice

security-alert@external-domain.example

72RISK / 100
01Authentication · sender evidence needs review
02Mail route · origin infrastructure reconstructed
03URL intelligence · reputation checks attached
04ML calibration · supporting context available
DETERMINISTIC SCORE + PROVIDER EVIDENCEOPEN REPORT →

One investigation surface

Every signal has a place in the story.

Start with the message. Follow the evidence through identity, infrastructure, reputation, and model-assisted context.

01 / INGEST

Gmail + Outlook

Connect the inboxes your team already uses, or upload a raw .eml message for a focused review.

02 / EVIDENCE

Deterministic analysis

Trace sender identity, authentication results, URLs, attachments, and mail routes with explainable rules.

03 / INTELLIGENCE

VirusTotal

Cross-check extracted URLs against a broad reputation dataset and preserve the provider evidence.

04 / INTELLIGENCE

URLScan

Look for observed URL infrastructure and connect provider reports back to the investigation.

05 / ASSIST

ML assistance

Use model calibration and contributor signals to add context without hiding the deterministic score.

06 / OUTCOME

Analyst-ready reports

Move from a suspicious message to a structured, evidence-backed investigation in one workspace.

How the work moves

Evidence first.
AI second.

ThreatTrace keeps the reasoning visible. Rules produce the baseline; enrichment and ML add context an analyst can inspect.

01

Connect or upload

Bring in Gmail, Outlook, or a raw message without changing your existing workflow.

02

Reconstruct the evidence

Inspect headers, authentication, sender relationships, URLs, attachments, and the mail route.

03

Decide with context

Review provider intelligence, ML calibration, and a plain-language recommended action.

Safety guides

Small habits that stop bigger scams.

Practical steps for pausing, verifying, and responding safely when an email does not feel right.

01

Spot a phishing email

Pause when a message creates urgency, uses a generic greeting, or asks for information unexpectedly. Check the sender address before you act.

02

Protect bank accounts

A bank will not ask for a password, PIN, or one-time code by email. Open your bank app or type its known address instead of following a message link.

03

If you clicked a link

Disconnect if something downloaded, run a malware scan, change exposed passwords from a trusted device, and contact the affected service directly.

04

Make it a family habit

Agree to verify unexpected requests together. A second pair of eyes is one of the simplest ways to stop a scam before it spreads.

Ready when you are

Give your next suspicious email a proper investigation.

Create a workspace, connect a mailbox when you need it, and keep the evidence close to the decision.

Create a free workspace