Phishing Email Analyzer — Instant Report Edition
automation · $49.99
Turn “Is this email phishing?” into a clear analyst report in under a minute.
Stop spending 20 minutes manually checking email headers, suspicious links, attachments, and sender domains.
This ready-to-use n8n workflow automatically analyzes suspicious emails and produces a clear, explainable phishing verdict without clicking dangerous links or building infrastructure from scratch.
What it does
Forward a suspicious email to your analysis mailbox, or send it directly to the webhook.
The workflow automatically checks:
Email authentication — SPF, DKIM, DMARC and originating IP
Impersonation — lookalike domains, homoglyphs, display-name spoofing and suspicious Reply-To addresses
URLs — shorteners, raw IPs, redirects, punycode and destination mismatches
Attachments — risky extensions, macros, archives and SHA-256 hashes
Email content — credential theft, payment fraud, urgency and QR-phishing indicators
Threat intelligence — optional VirusTotal, urlscan.io, AbuseIPDB and URLhaus enrichment
A verdict you can defend
No AI guessing.
A deterministic scoring engine produces:
Malicious · Suspicious · Likely Benign
Every score is backed by specific evidence, so your team can see why an email received its verdict.
Want an executive-friendly explanation? Enable optional AI summaries using Ollama or another supported model. AI can explain the result, but never change the verdict.
One analysis. Multiple outputs.
Get the finished report in:
Gmail · Slack · Discord · Webhook
The workflow can also return a simple answer to the person who reported the email, making it easy to turn phishing analysis into an internal security process.
Built for fast deployment
No database. No case-management system. No complicated infrastructure.
Import the workflow, activate it, send the included sample email, and start testing.
Turn suspicious emails into actionable reports automatically.
Need help?
Want to customize or deploy it for you? Get deployment & customization