Configure your mail environment so the tool can recognize internal systems and detect impersonation. All fields are optional and stored locally in your browser.
Mail System
Comma-separated hostnames or FQDNs. These will be recognized as internal Exchange servers in the hop timeline.
Comma-separated FQDNs of your hybrid connectors. Helps identify hybrid routing hops in the timeline.
Comma-separated hostnames or FQDNs of your Exchange servers.
Comma-separated hostnames. These will be recognized as internal mail servers in the hop timeline.
Your Google Workspace primary domain. Helps confirm inbound delivery hops.
Inbound Mail Filter / Gateway
If your gateway uses a non-standard hostname, enter it here. The tool will recognize it as your inbound filter in the hop timeline.
Outbound Mail Filter / Gateway
Outbound filter settings help identify your gateway in NDR / bounce-back message headers.
Non-standard outbound gateway hostname, if applicable.
Organization Domains
Comma-separated list of domains your organization owns and sends from. Used to detect lookalike domains and impersonation. Fill this in for best results.
Comma-separated list of known-good external domains (partners, vendors, ESPs). These are treated as legitimate and never flagged as lookalikes or spoofs.
Impersonation Protection
Comma-separated names or titles to watch for. If an external sender's display name contains one of these but sends from a domain not in your internal or trusted lists, it will be flagged as potential impersonation.
ℹ These settings power three Security Signals: lookalike domain detection, domain-in-display-name spoofing, and VIP name spoofing. Each check only runs when its relevant field is filled in.
Export Settings
Save your current settings to a file or copy them to share with a teammate or move to another machine.
Import Settings
Load a settings file, or paste exported settings JSON below.
🖨 Print / Export Report
Choose a report type or build a custom report. Output will be a light-theme PDF.
Include Sections
📋
Paste Email Headers
Copy full raw headers from your email client and paste below