emailtriage

Retired — functionality merged into phishprobe.

retired 2026-05-31

This tool has moved

emailtriage was a Python CLI for phishing-triage of .eml messages: header-chain analysis, Auth-Results extraction, HTML body scoring, attachment risk grading, and a verdict label (benign / spam-like / suspicious / likely-phishing). Every feature has been absorbed into phishprobe — the Rust replacement — with several enhancements the Python original didn't have:

Migration

# Old (emailtriage)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- emailtriage
emailtriage triage suspicious.eml

# New (phishprobe email)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- phishprobe
phishprobe email triage suspicious.eml
phishprobe email headers suspicious.eml
phishprobe email attachments suspicious.eml
phishprobe email score suspicious.eml          # numeric score + verdict, terse
cat suspicious.eml | phishprobe email triage -
phishprobe email triage suspicious.eml --format json
phishprobe email triage suspicious.eml --format markdown   # IR-ready report

Why retired?

emailtriage and phishprobe were duplicate-scope tools: phishprobe's URL analyzer already implements lexical phishing scoring with the same scoring engine emailtriage rebuilt for emails. Merging them means body URLs in an email automatically feed through the same lexical signals phishprobe uses for --url, so a phishy link in the body raises the email's overall verdict — a synergy that wasn't possible while emailtriage was a separate binary. The 2026-05-31 suite audit recommended absorbing emailtriage into phishprobe so the catalogue carries one phishing analysis tool rather than two.

Important caveat: phishprobe's email analysis currently treats Authentication-Results headers as header-trusted — i.e., we report what the receiving MTA emitted, not what we independently verified. Real DKIM / SPF / DMARC verification (DNS-backed) is planned as a follow-up but not in this build.

→ Go to phishprobe