All articles·Mail Forensics
Mail Forensics 1.6.0 · Free · Notarized by Apple New release · 1.6.0

Mail Forensics: understand email risk on your Mac

A visual investigation workspace for sender identity, authentication claims, delivery paths and optional AI content analysis.

Sep 11, 2026 8 min read 12 views 0 comments
Mail Forensics: understand email risk on your Mac
01

The problem

A message arrives with a familiar name, an ordinary subject and a request that seems reasonable. Before replying, paying or following a link, you want to understand who the message claims to come from and whether the evidence supports that story. A mail client is designed to make correspondence readable. The technical details that help answer those questions are usually somewhere else.

Mail Forensics brings those details into a native Mac workspace. You import a message, review a visual map of the available evidence and open the checks that deserve attention. Sender inconsistencies, authentication claims and delivery information become inspectable findings rather than an unexplained warning.

The app is useful when checking an unexpected invoice, an account request, a message that appears to impersonate a colleague or simply an email whose origin is unclear. It examines the messages you choose to import. It does not continuously monitor your inbox, replace your mail client or automatically block incoming mail.

The nine screenshots in this article were captured from the app’s native interface using fictional demonstration messages. Addresses and relay IPs are reserved examples. Network lookups are disabled and no AI request was submitted for these captures. The interface shown is in English; the explanations and captions are available in both languages.

02

Why it happens on macOS

An email has several layers. The displayed name may differ from the actual address. Replies can be directed to another domain. Authentication results may appear inside the message source, while Received headers describe the route reported by the mail servers. Mail Forensics reads these layers together and makes their provenance visible.

That distinction matters. An imported header saying “pass” is not, by itself, independent proof of the sender’s identity. Equally, missing authentication information does not establish that a personal email is fraudulent. The Authentication view preserves the reported outcomes and identifies imported claims as unverified. This version does not independently perform cryptographic verification of DKIM signatures.

The same care applies to the visual assessment. A red node indicates a strong indicator, yellow calls for review, green means that the particular check found no indicator in the available evidence, and gray identifies missing, unverified or unanalyzed information. The map does not turn those colors into a statistical probability of fraud. A green node does not certify an email, its links or its attachments.

A second demonstration message makes the distinction visible: a straightforward meeting confirmation has no contradictory identity indicator, so that node is green. Authentication, infrastructure and content checks remain visibly incomplete. The absence of a finding and the absence of a check are represented separately.

A fictional meeting confirmation: no identity inconsistency was found, while gray nodes keep incomplete checks visible.
A fictional meeting confirmation: no identity inconsistency was found, while gray nodes keep incomplete checks visible.
03

My approach

Start with the message

Drag a message from Apple Mail or another supported mail client into the app. When the client supplies a compatible message source or promised file, there is no need to save the email to a folder first. Compatibility depends on what the originating client exposes during the drag. You can also open EML or EMLX files, import several messages together, or paste raw source and headers. Supplying only headers necessarily limits what can be analyzed later.

The starting workspace accepts dragged messages, email files and pasted source.
The starting workspace accepts dragged messages, email files and pasted source.

A workspace organized around the evidence

Overview is the starting point for each investigation. Its connected map separates technical checks from optional AI content checks. The technical branch covers identity, authentication, mail infrastructure and domain indicators. The content branch covers payment requests, credentials, impersonation, deceptive links, pressure and urgency, and other content. Selecting a node opens the evidence behind its status. The technical report and explanation remain available below the map.

The left navigator opens each specialist view without losing the selected message. Session history holds up to twenty imported messages while the app stays open. Search by sender, subject, Message-ID or filename, combine the search with a risk filter, and return to an earlier investigation. The inspector on the right keeps source details, size, recipients and the claimed sender domain nearby.

Findings you can examine

Findings shows the observations behind the technical assessment, with severity labels and searchable evidence. In our fictional payment message, the displayed address differs from the actual sender, and replies go to a third domain. Those are concrete discrepancies to investigate. Imported authentication failures are shown with their uncertainty rather than silently promoted to independently verified facts.

Findings separates a display-name discrepancy, a different reply destination and unverified authentication claims.
Findings separates a display-name discrepancy, a different reply destination and unverified authentication claims.

Authentication without hiding the source

The Authentication page groups SPF, DKIM and DMARC outcomes, shows the reporting service and preserves the underlying values. DKIM signature details include the claimed signing domain, selector and algorithm. This helps you see what the source actually says, including missing or conflicting information, before drawing a conclusion.

Authentication displays the supplied SPF, DKIM and DMARC results and marks their imported provenance.
Authentication displays the supplied SPF, DKIM and DMARC results and marks their imported provenance.

Follow the reported delivery path

Delivery path organizes Received headers into a relay chain with hostnames, addresses, reported protocols and timestamps. You can inspect individual hops and compare the timing information. These are the route claims contained in the email: a relay address is not the physical location or personal identity of the author.

Two fictional relay hops, with their reported protocols and timing.
Two fictional relay hops, with their reported protocols and timing.

Choose when to use network information

With Network enabled, the app can enrich an investigation using relay geolocation, IP reputation checks, reverse DNS and domain registration information. The Network checks page exposes the state of each lookup independently. A service failure remains unavailable evidence; it is not converted into a clean result. Checks can be stopped or retried.

Switch Network off for header-only analysis. The technical reading happens locally; enrichment sends relevant address or domain queries to external lookup services. The screenshot deliberately shows the disabled state, so no demonstration address is presented as a real network finding.

Network checks distinguishes lookups that have not run from completed results.
Network checks distinguishes lookups that have not run from completed results.

Return to the original evidence

Source & headers provides parsed message fields, header inspection, authentication details and raw source. It is the place to compare an explanation with the data that produced it. A readable overview is useful; being able to inspect the original fields makes it possible to question that overview.

The source inspector keeps parsed identity fields alongside access to headers, authentication and raw source.
The source inspector keeps parsed identity fields alongside access to headers, authentication and raw source.

Optional AI, with your own provider

AI Settings supports OpenAI, Anthropic Claude and DeepSeek. Choose the provider and model, save your API key in macOS Keychain and test the connection. Saving the key and successfully testing model access are separate operations with separate feedback. The connection test does not send email content.

Actual message analysis starts from Overview with Add AI analysis. Without a configured key, the app directs you to setup. You can choose whether to include the message text, apply masking to common personal identifiers, limit the input and inspect a prepared preview. Masking reduces some exposure but is not guaranteed anonymization. The selected material goes to your chosen provider under its data policy and uses your API credits. Attachments are excluded, and extracted links are not opened by the AI preview builder.

The returned assessment combines a written summary, categorized findings, quoted evidence, limitations and suggested actions with the content branch of the map. It supplements the technical evidence. Ordinary wording does not erase a sender inconsistency, and a model’s opinion does not establish authenticity. The screenshots show the setup and unassessed content nodes, without presenting a simulated response as a live AI result.

AI Settings contains provider selection, the empty secure key field, connection testing and input privacy controls.
AI Settings contains provider selection, the empty secure key field, connection testing and input privacy controls.

Keep a report and stay informed

Copy the current analysis as text, export a PDF report for reading or sharing, or save structured JSON evidence. These exports document the investigation at that moment, including the available results and their limits. Session history itself is temporary, so export the material you need to retain.

Mail Forensics 1.6.0 is a free direct download for Apple silicon Macs running macOS 14 Sonoma or later. The app and DMG are signed with Developer ID and notarized by Apple. It requires no Mail Forensics account; optional AI service usage is billed separately by your provider.

The app checks the signed release channel automatically while open, normally every six hours, and also provides Check for Updates in its menu. A newer compatible build produces an update notice. Version 1.6.0 does not automatically download or install the update. The download panel on this page reads the published channel so you can find the current release here.

Download Mail Forensics for Mac

macOS 14 Sonoma or later · Apple silicon · Version 1.6.0

Download for macOS
All articles

Discussion 0 comments

No comments yet. Start the conversation.

More from the codex