An offline reader for e-mail headers: it redraws the route a message took, reports the authentication the receiving server recorded, and grades what it finds — without ever calling a message safe.
A phishing e-mail is a confidence trick played on one line: the name in the From field. People read that name, recognise it, and stop reading — which is exactly what the rest of the headers are there to catch.
Every server that touches a message stamps its own line onto it. Those stamps say where it really came from, whether anyone authenticated it, and whether its route agrees with its claims. Herald reads them and explains them in plain words.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| SPF | failed, soft-failed, or no usable policy |
| DKIM | signature failed, present but unverified, or absent |
| DMARC | failed alignment, or no policy published |
| Envelope | From and Return-Path on different registrable domains |
| Reply-To | replies routed to a domain that is not the sender |
| Display name | a name hiding a different real address |
| Look-alike | a punycode domain, or digit-for-letter spelling |
Herald reads the verdict the receiving server already wrote down. It fetches no DNS key, re-checks no signature, and never sees your own filtering. A message with no authentication at all is capped at C and labelled unknown, rather than waved through.
git clone https://github.com/at0m-b0mb/Herald-Email-Headers.git
cd Herald-Email-Headers
python3 -m pip install -r requirements.txt
python3 -m herald # the window
python3 -m herald samples/ # the command line
python3 -m pytest -q # 158 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.