Open-source analyzer for suspicious emails, texts, URLs, and phone numbers. Paste it, run analysis, get a verdict built from evidence โ an unknown is never marked safe.

RFC 822 parsing with folded headers, SPF / DKIM / DMARC result analysis, and sender vs Reply-To comparison.
Direct-IP, punycode, shortener, user-info, suspicious-TLD and lookalike detection across extracted URLs, domains, emails, and phone numbers.
Cloudflare malware/phishing DNS checks, Quad9 threat blocking, RDAP domain age, and optional VirusTotal, Web Risk, and AbuseIPDB.
Urgency, credential, payment, and irreversible-payment scoring โ verdict aggregation that never turns an unknown into 'safe'.
Regex detectors, extraction, and lookalike checks run right in the browser with no accounts or API keys.
Reports saved to a private Supabase workspace with row-level security, or locally in your browser.




git clone https://github.com/p-romeo/signal-vaultnpm install && npm run dev (Node.js 22+).dev.vars for deeper reputation checks.SignalVault supports decisions but never guarantees something is safe โ failed or missing provider results stay explicit. The worker never visits submitted destinations, and evidence stays in your own workspace.