CHECKLINK AI
Local email identity chain

Email Identity Checker

See whether the visible sender, reply path, authenticated domains, message infrastructure, and linked destinations align.

Tool guidance

How to use this tool

Headers and body remain local. Only a selected domain or URL is sent for the specific DNS or scanner action you request.

How to use it

Paste full raw headers and optionally the body.
Add the organization and official domain you expected.
Compare every identity in the chain.
Choose whether to check public DNS or scan individual URLs.

What results mean

Differences need explanation, not automatic accusations.
Missing SPF, DKIM, or DMARC is not proof.
Authentication pass does not make message content safe.

What to do next

Retrieve full original headers if data is missing.
Verify sensitive requests from the official service.
Use Phishing First Aid if secrets or money were already shared.
Browser extension

CheckLink browser extension

Open the current page, inspect links from the browser menu, and jump into CheckLink faster without an account.

Works with Chrome and compatible Chromium-based desktop browsers. Firefox and Safari versions are not currently available.

CheckLink browser extension preview

The extension sends a URL only when you choose a scan action. It does not store scan history.

Headers and body stay in this browser tab. Only a domain selected for DNS lookup or a URL selected for scanning is sent to the server.

Research-informed, not a guarantee

Context and combinations matter

Manipulation cues are evidence, not proof. One urgent, authoritative, emotional, or personalized phrase cannot establish phishing.

Technically experienced users can still be deceived. Self-reported knowledge is not treated as proof of resilience.

Age, gender, nationality, education, profession, and other demographic attributes are not collected or used in results.

No score here is claimed to be scientifically validated. Independently verify sensitive requests through an official channel.