Features
Everything Rubiscout does
From a single paste of raw headers, Rubiscout runs the full chain โ AI forensics, live DNS checks, IP reputation lookups, and generates a report you can share or print.
AI Investigation
Investigative Bench
An AI-powered chat interface appears after every analysis. Ask follow-up questions with full email context already baked in โ no need to re-paste anything.
Context-Aware Suggested Questions
The bench surfaces 4 suggested questions tailored to the risk level โ Critical analyses get immediate response guidance, Low risk gets verification questions.
Draft Ready-to-Use Content
Ask Claude to draft IT security alerts, HR notices, phishing reports, or emails to your bank's fraud team โ it produces complete copy-paste text, not generic templates.
Multi-Turn Investigation
Ask as many follow-up questions as you need. Claude remembers the full conversation context so you can dig progressively deeper without repeating yourself.
Analysis
Plain-English Verdict
Every analysis opens with a single sentence written for a non-technical reader โ clearly stating whether the email is dangerous, suspicious, or safe, and what to do.
AI-Powered Header Forensics
Claude reads all header fields together โ routing hops, authentication results, display-name vs. address mismatches, Reply-To anomalies โ and explains what it found.
Risk Score
A four-level risk rating (Low / Medium / High / Critical) with a detailed explanation of exactly which signals drove the score.
Authentication Breakdown
SPF, DKIM, and DMARC results extracted from the header and displayed with color-coded pass/fail/softfail badges.
Origin & Routing Path
The originating IP address, geolocation country flag, and a step-by-step trace of every mail server the message passed through.
Sender Field Analysis
From, Return-Path, and Reply-To extracted and compared โ mismatches between these fields are a primary indicator of spoofing and BEC attacks.
Hop Timing Visualization
The routing path is shown as a color-coded visual timeline โ green for normal delays, yellow/orange for slow hops, red for delays over 30 minutes. Suspicious delays are automatically flagged as potential botnet or relay indicators.
Verification
Live DNS Validation
Real-time DNS lookups at analysis time retrieve the sending domain's actual SPF and DMARC records โ then compare them to what the headers claim. Discrepancies are flagged immediately.
IP Reputation Check
The sending IP is checked against five major DNSBL blacklists โ Spamhaus ZEN, SpamCop, Barracuda, SORBS, and SpamRATS โ using pure DNS. No API key, no external service dependency.
Guidance
Actionable Recommendations
3โ5 specific steps tailored to this exact email's threat profile. Not "check your spam settings" โ concrete actions like "forward to your bank's fraud team at reportphishing@..." or "do not click โ report via your company's incident response portal."
How to Extract Headers Guide
Built-in step-by-step instructions for finding raw email headers in Gmail, Outlook (desktop), Outlook Web, Apple Mail, and Yahoo Mail โ with a modal that opens without leaving the page.
Sharing & Reporting
Shareable Analysis Links
Every analysis gets a permanent URL (/analysis/[id]) you can share with colleagues, IT teams, or security researchers. No account required.
Phishing Incident Report
For Critical and High risk emails, a professional printable report is generated โ covering verdict, risk score, authentication results, sender details, routing path, and recommended actions. Print or save as PDF in one click.
Community & UX
Community Analysis Counter
A live count of all email headers analyzed by the Rubiscout community โ a persistent global tally that grows with every submission.
Recent Analysis History
Your last 10 analyses from the past 30 days are shown below the input so you can quickly revisit a previous result.
Font Size Toggle
Switch between Small, Medium, and Large text sizes โ your preference is saved in the browser so it persists across sessions.
Character Counter & Limit
A live character count with a 50,000-character limit and an early warning at 40,000 โ very large headers are flagged before submission.