Features

Everything Rubiscout does

AI forensics, live DNS checks, IP reputation, spam scoring, ARC validation, community verdicts, and a streaming investigation API — from a paste, a drag-and-drop, or a forwarded email.

Analysis

Plain-English Verdict

Every analysis opens with a single sentence for a non-technical reader — safe, suspicious, or dangerous.

Risk Score

Four-level rating (Low / Medium / High / Critical) with 2–4 specific signals that drove the score.

Actionable Recommendations

3–5 specific next steps tailored to the threat profile of this exact email — not generic advice.

AI Header Forensics

Rubiscout's AI reads all header fields together — routing, auth results, display-name mismatches, Reply-To anomalies.

Sender Field Analysis

From, Return-Path, and Reply-To extracted and compared — mismatches are the primary indicator of spoofing and BEC.

Spam Score

15-rule heuristic engine scores email body content 0–10 across auth signals, subject keywords, URL reputation, and MIME structure.

MIME Structure

Part tree with attachment detection and dangerous extension flagging (.exe, .ps1, .docm, archives, and more).

CAN-SPAM Compliance

Seven checks — From/Date/Message-ID headers, List-Unsubscribe, plain-text alternative, physical address, non-deceptive subject.

AI Investigation

Investigative Bench

An AI chat panel stays visible alongside every analysis — ask follow-up questions with full email context already loaded.

Tailored Questions

Four questions are generated per analysis, focused on the specific risk signals found — not generic prompts.

Draft Security Content

Ask the bench to write IT alerts, HR notices, phishing reports, or fraud team emails — complete copy-paste text.

Multi-Turn Conversation

Rubiscout remembers the full thread so you can dig progressively deeper without repeating yourself.

Authentication & DNS

SPF / DKIM / DMARC Gauge

Semicircular compliance gauge with alignment mode (relaxed or strict) and the published DMARC enforcement policy.

ARC Chain Validation

Per-hop SPF/DKIM/DMARC results across forwarding hops — chain length and whether the seal is intact.

Live DNS Validation

Real-time lookups at analysis time for SPF, DMARC, MTA-STS, TLS-RPT, and BIMI records.

IP Reputation

Sending IP checked against five DNSBLs — Spamhaus ZEN, SpamCop, Barracuda, SORBS, and SpamRATS.

Origin & Routing Path

Originating IP, geolocation country, and a step-by-step trace of every mail server the message passed through.

Hop Timing

Routing path shown as a color-coded bar chart — green for normal delays, amber for slow, red for delays over 30 minutes.

DNSSEC Check

DNSKEY lookup for the sender domain — shows whether the zone is signed and whether the signature validates.

FCrDNS Lookup

Forward-confirmed reverse DNS — verifies the PTR record resolves back to the same IP.

Intake

Forward to Analyze

Forward any suspicious email to analyze@rubiscout.com and receive a complete analysis reply within seconds.

Paste Headers or Full Email

Paste just the raw headers or the entire email including body — body content adds spam and URL signals.

Drag & Drop .eml

Drag an email file onto the input area — Rubiscout reads it and populates the field automatically.

Browser Bookmarklet

Click the bookmarklet on any raw-email page and Rubiscout opens with headers pre-filled, ready to analyze.

Sharing & Reporting

Shareable Links

Every analysis gets a permanent URL you can share with colleagues, IT teams, or security researchers.

PDF Incident Report

Printable phishing incident report covering verdict, auth results, sender, routing, and recommendations.

Body Preview

Plain-text and sanitized HTML preview of the email body — scripts, remote images, and event handlers stripped.

Raw Header View

Toggle between extracted key fields and a full formatted view of the raw header — field names highlighted, fully scrollable.

API & Automation

POST /investigate (SSE)

Streaming agent endpoint — Rubiscout's agent (powered by Claude Opus) runs five live tools and delivers IOCs, TTPs, and SOC recommendations over SSE.

POST /analyze

Fast JSON endpoint — submit raw headers, get a full forensic verdict, auth results, DNS checks, and risk score in 3–8 s.

MCP Server

Install with npx rubiscout-mcp — exposes analyze_email, get_analysis, and list_analyses to Claude Code, Cursor, and other MCP-compatible agents. Requires a free API key.

Official CLI

npm package (rubiscout) with analyze, list, get, and config commands — JSON output, file or stdin input.

API Reference

Full OpenAPI 3.1 spec rendered by Scalar at /api-reference — live try-it console, curl examples, SSE event schemas.

Docs

Complete documentation covering all intake methods, result tabs, streaming agent, CLI, MCP setup, and Python examples.

Community & Privacy

No Account Required to Analyze

Paste, drag-and-drop, or forward an email on the site — no sign-up, no login, no tracking. An account is only needed for programmatic access (API, CLI, MCP).

Free API Key

Sign up at /dashboard for a free API key — required to call the REST API, CLI, or MCP server. No credit card during beta.

Recipient PII Never Stored

To:, Delivered-To:, and X-Original-To: are stripped before any data is written to the database.

Community Verdicts

Security researchers can tag any shared analysis — phishing, BEC, spam, legitimate, unknown — shown as a distribution chart.

Research Opt-In

Optionally contribute an analysis to Rubiscout's research dataset — sender-side headers only, no recipient data.

Install the Bookmarklet

1

Show your bookmarks bar

Press ⌘+Shift+B to make the bookmarks bar visible — you need it to install the bookmark.

2

Drag this to the bar

Rubiscout: Analyze
3

Use it on any raw email

Open your email's raw source, then click the bookmark. Rubiscout opens with the headers pre-filled.

How to open raw headers in your email client

Gmail

  1. 1.Open the email
  2. 2.Click ⋮ (More)
  3. 3.Select 'Show original'

Outlook

  1. 1.Open the email
  2. 2.Click ⋯ (More actions)
  3. 3.Select 'View message source'

Apple Mail

  1. 1.Open the email
  2. 2.View menu → Message
  3. 3.Click 'Raw Source'

Yahoo Mail

  1. 1.Open the email
  2. 2.Click More (⋯)
  3. 3.Select 'View raw message'