Features
Everything Rubiscout does
AI forensics, live DNS checks, IP reputation, spam scoring, ARC validation, community verdicts, and a streaming investigation API — from a paste, a drag-and-drop, or a forwarded email.
Analysis
Plain-English Verdict
Every analysis opens with a single sentence for a non-technical reader — safe, suspicious, or dangerous.
Risk Score
Four-level rating (Low / Medium / High / Critical) with 2–4 specific signals that drove the score.
Actionable Recommendations
3–5 specific next steps tailored to the threat profile of this exact email — not generic advice.
AI Header Forensics
Rubiscout's AI reads all header fields together — routing, auth results, display-name mismatches, Reply-To anomalies.
Sender Field Analysis
From, Return-Path, and Reply-To extracted and compared — mismatches are the primary indicator of spoofing and BEC.
Spam Score
15-rule heuristic engine scores email body content 0–10 across auth signals, subject keywords, URL reputation, and MIME structure.
MIME Structure
Part tree with attachment detection and dangerous extension flagging (.exe, .ps1, .docm, archives, and more).
CAN-SPAM Compliance
Seven checks — From/Date/Message-ID headers, List-Unsubscribe, plain-text alternative, physical address, non-deceptive subject.
AI Investigation
Investigative Bench
An AI chat panel stays visible alongside every analysis — ask follow-up questions with full email context already loaded.
Tailored Questions
Four questions are generated per analysis, focused on the specific risk signals found — not generic prompts.
Draft Security Content
Ask the bench to write IT alerts, HR notices, phishing reports, or fraud team emails — complete copy-paste text.
Multi-Turn Conversation
Rubiscout remembers the full thread so you can dig progressively deeper without repeating yourself.
Authentication & DNS
SPF / DKIM / DMARC Gauge
Semicircular compliance gauge with alignment mode (relaxed or strict) and the published DMARC enforcement policy.
ARC Chain Validation
Per-hop SPF/DKIM/DMARC results across forwarding hops — chain length and whether the seal is intact.
Live DNS Validation
Real-time lookups at analysis time for SPF, DMARC, MTA-STS, TLS-RPT, and BIMI records.
IP Reputation
Sending IP checked against five DNSBLs — Spamhaus ZEN, SpamCop, Barracuda, SORBS, and SpamRATS.
Origin & Routing Path
Originating IP, geolocation country, and a step-by-step trace of every mail server the message passed through.
Hop Timing
Routing path shown as a color-coded bar chart — green for normal delays, amber for slow, red for delays over 30 minutes.
DNSSEC Check
DNSKEY lookup for the sender domain — shows whether the zone is signed and whether the signature validates.
FCrDNS Lookup
Forward-confirmed reverse DNS — verifies the PTR record resolves back to the same IP.
Intake
Forward to Analyze
Forward any suspicious email to analyze@rubiscout.com and receive a complete analysis reply within seconds.
Paste Headers or Full Email
Paste just the raw headers or the entire email including body — body content adds spam and URL signals.
Drag & Drop .eml
Drag an email file onto the input area — Rubiscout reads it and populates the field automatically.
Browser Bookmarklet
Click the bookmarklet on any raw-email page and Rubiscout opens with headers pre-filled, ready to analyze.
Sharing & Reporting
Shareable Links
Every analysis gets a permanent URL you can share with colleagues, IT teams, or security researchers.
PDF Incident Report
Printable phishing incident report covering verdict, auth results, sender, routing, and recommendations.
Body Preview
Plain-text and sanitized HTML preview of the email body — scripts, remote images, and event handlers stripped.
Raw Header View
Toggle between extracted key fields and a full formatted view of the raw header — field names highlighted, fully scrollable.
API & Automation
POST /investigate (SSE)
Streaming agent endpoint — Rubiscout's agent (powered by Claude Opus) runs five live tools and delivers IOCs, TTPs, and SOC recommendations over SSE.
POST /analyze
Fast JSON endpoint — submit raw headers, get a full forensic verdict, auth results, DNS checks, and risk score in 3–8 s.
MCP Server
Install with npx rubiscout-mcp — exposes analyze_email, get_analysis, and list_analyses to Claude Code, Cursor, and other MCP-compatible agents. Requires a free API key.
Official CLI
npm package (rubiscout) with analyze, list, get, and config commands — JSON output, file or stdin input.
API Reference
Full OpenAPI 3.1 spec rendered by Scalar at /api-reference — live try-it console, curl examples, SSE event schemas.
Docs
Complete documentation covering all intake methods, result tabs, streaming agent, CLI, MCP setup, and Python examples.
Community & Privacy
No Account Required to Analyze
Paste, drag-and-drop, or forward an email on the site — no sign-up, no login, no tracking. An account is only needed for programmatic access (API, CLI, MCP).
Free API Key
Sign up at /dashboard for a free API key — required to call the REST API, CLI, or MCP server. No credit card during beta.
Recipient PII Never Stored
To:, Delivered-To:, and X-Original-To: are stripped before any data is written to the database.
Community Verdicts
Security researchers can tag any shared analysis — phishing, BEC, spam, legitimate, unknown — shown as a distribution chart.
Research Opt-In
Optionally contribute an analysis to Rubiscout's research dataset — sender-side headers only, no recipient data.
Install the Bookmarklet
Show your bookmarks bar
Press ⌘+Shift+B to make the bookmarks bar visible — you need it to install the bookmark.
Drag this to the bar
Use it on any raw email
Open your email's raw source, then click the bookmark. Rubiscout opens with the headers pre-filled.
How to open raw headers in your email client
Gmail
- 1.Open the email
- 2.Click ⋮ (More)
- 3.Select 'Show original'
Outlook
- 1.Open the email
- 2.Click ⋯ (More actions)
- 3.Select 'View message source'
Apple Mail
- 1.Open the email
- 2.View menu → Message
- 3.Click 'Raw Source'
Yahoo Mail
- 1.Open the email
- 2.Click More (⋯)
- 3.Select 'View raw message'