emailtriage
Retired — functionality merged into phishprobe.
retired 2026-05-31This tool has moved
emailtriage was a Python CLI for phishing-triage of .eml
messages: header-chain analysis, Auth-Results extraction, HTML body
scoring, attachment risk grading, and a verdict label
(benign / spam-like / suspicious / likely-phishing). Every feature
has been absorbed into
phishprobe — the Rust
replacement — with several enhancements the Python original
didn't have:
- Homograph / IDN attack detection on the From: domain and every body URL (mixed-script and Cyrillic look-alikes).
- Display-name spoofing check against a known-brand allow-list.
- Magic-byte verification on attachments (catches
.pdf.exeeven when filename + Content-Type both lie). - Three-way Return-Path / Reply-To / From mismatch.
- Received-chain time-skew + missing-PTR markers.
- Body URLs scored by phishprobe's URL analyzer — a phishy link in the body raises the email's verdict.
- Operator pivot URLs for VirusTotal (per attachment SHA-256, per body domain), urlscan.io (per body URL), and crt.sh (sender domain).
- Markdown report output for IR write-up inclusion.
Migration
# Old (emailtriage)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- emailtriage
emailtriage triage suspicious.eml
# New (phishprobe email)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- phishprobe
phishprobe email triage suspicious.eml
phishprobe email headers suspicious.eml
phishprobe email attachments suspicious.eml
phishprobe email score suspicious.eml # numeric score + verdict, terse
cat suspicious.eml | phishprobe email triage -
phishprobe email triage suspicious.eml --format json
phishprobe email triage suspicious.eml --format markdown # IR-ready report
Why retired?
emailtriage and phishprobe were duplicate-scope tools: phishprobe's
URL analyzer already implements lexical phishing scoring with the
same scoring engine emailtriage rebuilt for emails. Merging them
means body URLs in an email automatically feed through the same
lexical signals phishprobe uses for --url, so a phishy
link in the body raises the email's overall verdict — a synergy
that wasn't possible while emailtriage was a separate binary.
The 2026-05-31 suite audit recommended absorbing emailtriage into
phishprobe so the catalogue carries one phishing analysis tool
rather than two.
Important caveat: phishprobe's email analysis currently treats Authentication-Results headers as header-trusted — i.e., we report what the receiving MTA emitted, not what we independently verified. Real DKIM / SPF / DMARC verification (DNS-backed) is planned as a follow-up but not in this build.