Drop in the .eml or .emlx files a mail client exports and read them the way a mailbox would: the rendered message with its inline images, every header, the authentication verdicts, and the attachments. Parsed in your browser; nothing is uploaded.
An .eml file is one email saved exactly as mail servers pass it between themselves (RFC 5322 with a MIME body): headers, the HTML and plain-text versions, and every attachment, usually base64 or quoted-printable encoded in whatever character set the sender chose. Gmail writes one when you choose Download message, Thunderbird when you save a message, and Apple Mail stores the same thing in a thin .emlx wrapper, which this viewer also reads.
Double-clicking an .eml hands it to whatever mail program claims the extension, often one you never set up. Nothing about the file needs a mail client. Drop it here and it is decoded where it is, in a sandbox where nothing in the message can run.
The HTML part, with cid: inline images resolved from the file itself, in a sandbox with scripts and forms disabled.
Blocked by default. Loading a remote image tells the sender the message was opened, so it is your choice.
SPF, DKIM and DMARC badges read from the receiver's Authentication-Results header.
Every part with a filename or Content-ID, downloadable individually.
.msg is differentOutlook's .msg is a binary format, not MIME. Renaming it does not convert it; export as .eml instead.
winmail.datOutlook rich-text (TNEF) packaging with the real attachments sealed inside. The fix is at the sender's end.
Gmail: open the message, ⋮ → Download message. Outlook on the web: ⋯ → Download. Thunderbird: File → Save As. Apple Mail: File → Save As, format Raw Message Source.
The message declares one character set and contains another. The viewer decodes what the message declares; if that is wrong, the Source tab shows the raw bytes.
Yes. Use the Render in real inboxes button: the same file is delivered to real Gmail, Outlook.com and Yahoo Mail accounts and screenshotted, free.
Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.
Highlight spam-trigger phrases, ALL-CAPS, exclamation runs and emoji in a subject and body, with a rewrite.
Drop in DMARC aggregate reports (XML, .gz, .zip) to see pass rates, failing sources and what to fix.
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.