These addresses all land in the one inbox below. Click any to copy it and make it the one shown above.
Waiting for mail...
Drop a .eml or .msg-exported message here, or click to chooseRead in this tab, never uploaded
Or paste the message source, or just its headers:
The honest notes
Nothing is uploaded. Static page, no endpoint, no account. The message is read from disk into this tab and never leaves it. There is also no lookup: the checker cannot make a request to any other domain at all, which is a rule your browser enforces rather than a promise from us.
Nothing in the message is loaded, ever. The trackers are found, named and counted from the source text. Fetching one to "check" it is precisely the act that tells the sender you opened the message, so nothing here does, and the security policy would refuse it anyway.
The authentication results are read, not recomputed. SPF depends on the IP address that connected, which is not in the message, and DKIM needs a DNS lookup. What the headers carry is the verdict your provider reached when it could check both. That is the real answer, recorded by the only party in a position to work it out, and it is why this can be honest without making a single request.
Which means the headers have to be genuine. Everything below the first server you actually trust can be invented by the sender. If somebody emails you a suspicious message as an attachment, you are reading their copy, and a determined forger could have written those lines themselves. Headers taken from your own mailbox are the ones worth trusting.
Passing is not the same as safe. A great deal of spam and plenty of fraud passes SPF, DKIM and DMARC perfectly, because the sender really does own the domain they are sending from. All a pass proves is that the From line is not forged. Whether the person behind it is honest is a different question and this cannot answer it.
Failing is not always fraud. Mailing lists rewrite messages in ways that break DKIM, and forwarding routinely breaks SPF. A failure means the message cannot be proven genuine, which is worth knowing and is not a conviction.
It errs towards saying nothing. A tool that flags every ordinary email is one you learn to ignore, so an unremarkable message comes back with an empty list rather than a manufactured worry.
The tracker list is deliberately generous. A one-pixel transparent image is the textbook case and increasingly the rare one; the modern version is a normal-looking image on a marketing platform with your identifier in the path. Both are listed, and so is any plain remote image, because loading one still hands over your IP address and the moment you read it.
These addresses belong to this tab and survive a refresh. New address adds another and keeps the old ones, all reading into the one inbox; Delete removes the one on top; closing the tab forgets them all. Each message deletes itself an hour after it arrives.
A disposable address for the forms that do not deserve your real one, and a
checker for the mail you already got. The rail on the left is which of the two
you are looking at.
A disposable address that reads its own mail, and a checker that
tells you who really sent a message and who is watching you read it. Both
answers are already inside the message, so no lookup is needed and none is made.
This is not private, and not for anything that matters.
The address below is public in the only way that counts: it has no password, so
anyone who learns it can read everything it receives. It is unguessable, which
is the whole of its security, so do not post it anywhere and do not reuse it.
Use it for a signup you do not trust, a one-off verification code, a download
that wants an address first: the places you would rather not hand your real
inbox. Do not use it for anything you would mind a stranger
reading, for password resets on accounts you care about, or for anything you
need to keep. Messages are deleted an hour after they arrive, and everything is
gone the moment you burn the inbox or the sweep runs.
Mail sent here does pass through this site's server to be stored for that hour,
so unlike the checker beside it this half is not "nothing leaves your machine."
It is the honest exception, like the delete-posts tool: a small, stated amount
of server, fenced off and short-lived. Nothing you would call private should go
near it.
Where do I find the headers?
Gmail: open the message, the three dots at the top right, “Show original”. Copy the whole thing.
Outlook: open the message in its own window, File, Properties, and copy the “Internet headers” box. That gives you headers only, which is enough for the sender check but not for the tracker check.
Apple Mail: View, Message, Raw Source.
Thunderbird: Ctrl-U, or More, View Source.
Anywhere: save or drag the message out as a .eml file and drop it above. That is the whole message, so both halves work.
The checker: the honest notes
Nothing is uploaded. Static page, no endpoint, no account. The message is read from disk into this tab and never leaves it. There is also no lookup: the checker cannot make a request to any other domain at all, which is a rule your browser enforces rather than a promise from us.
Nothing in the message is loaded, ever. The trackers are found, named and counted from the source text. Fetching one to "check" it is precisely the act that tells the sender you opened the message, so nothing here does, and the security policy would refuse it anyway.
The authentication results are read, not recomputed. SPF depends on the IP address that connected, which is not in the message, and DKIM needs a DNS lookup. What the headers carry is the verdict your provider reached when it could check both. That is the real answer, recorded by the only party in a position to work it out, and it is why this can be honest without making a single request.
Which means the headers have to be genuine. Everything below the first server you actually trust can be invented by the sender. If somebody emails you a suspicious message as an attachment, you are reading their copy, and a determined forger could have written those lines themselves. Headers taken from your own mailbox are the ones worth trusting.
Passing is not the same as safe. A great deal of spam and plenty of fraud passes SPF, DKIM and DMARC perfectly, because the sender really does own the domain they are sending from. All a pass proves is that the From line is not forged. Whether the person behind it is honest is a different question and this cannot answer it.
Failing is not always fraud. Mailing lists rewrite messages in ways that break DKIM, and forwarding routinely breaks SPF. A failure means the message cannot be proven genuine, which is worth knowing and is not a conviction.
It errs towards saying nothing. A tool that flags every ordinary email is one you learn to ignore, so an unremarkable message comes back with an empty list rather than a manufactured worry.
The tracker list is deliberately generous. A one-pixel transparent image is the textbook case and increasingly the rare one; the modern version is a normal-looking image on a marketing platform with your identifier in the path. Both are listed, and so is any plain remote image, because loading one still hands over your IP address and the moment you read it.
The inbox: the honest notes
It is receive-only, on purpose. You cannot send from this address, only read what arrives. That removes the hardest and most abusable half of running email, and it is all a disposable inbox needs.
Every message is checked, not just shown. The same reader the Check a message tab uses runs over each incoming message, so a disposable inbox also tells you whether the sender was forged (SPF, DKIM, DMARC) and lists any tracking pixels or click-wrappers it found. A verification code is safe to read; a "confirm your password" is flagged for what it is.
Nothing is rendered as a live web page. A message is reduced to plain text before it is stored, and shown as text. Remote images, scripts and trackers never load, so opening a message here cannot report back that you did, and cannot run anything.
It expires, and it is swept. A message carries a deletion time an hour out; a scheduled job deletes expired ones, and every read also filters them out, so an expired message is never shown even if the sweep is late. Burn removes everything for the address immediately.
The address is the only secret. There is no login. Fourteen random characters is about seventy bits, which is not guessable, but it is the whole of the protection: treat the address itself as the password, because it is.
You can hold several at once, like a wallet holds addresses. New address does not throw the old one away: it keeps receiving, and every address you are holding reads into the same inbox, each message tagged with which one it arrived at. Up to eight at a time, so the tab is not polling forever; Delete removes the one on top, and Delete every inbox clears them all. It is the shape a disposable inbox wanted: one for each signup, all in one window.
The tab remembers the addresses, and only the addresses. The list is kept in this tab's session storage so a refresh does not lose a code that is mid-flight; closing the tab forgets them. No message content is ever stored in your browser.
This half runs on a server, and says so. Receiving mail needs somewhere for it to land, so the inbox, alone among the tools here, stores data on this site's infrastructure for a short while. It is the reason it lives behind its own warning and holds nothing you would not shout across a room.
Nothing here is for sale, nothing is tracked, and there is no account to make.
If something saved you an hour: 83TQcTwusSQ4WKbPQE5osrF3cR4GWe2zmcNWeozK6BSqHSaeLvjUVe476ouVwLKn1uVwEFcbJQvnme7W6dTV5SB93x45DEy
You can
check that address here before sending anything.