Use the original email when you can
An EML export preserves more information than a screenshot or copied paragraph. Upload the original message from your mail application. If you only have the body, choose the message check and paste the wording.
The advisor extracts sender and Reply-To addresses, links and attachment names. Exported authentication headers are treated as unverified until the receiving mail system confirms their origin.
Look at the request as well as the sender
A real mailbox can be compromised. Consider what the message asks you to do, whether the request fits the relationship, and whether it changes a payment destination or asks for credentials. A signature block or previous conversation can be copied.
- Compare the actual email address with the contact in your records.
- Check whether replies go to another domain.
- Verify unexpected payment or account changes through a known contact.
- Keep the original email if an investigation is needed.
Using DSDillon Mail
Mail’s security view provides the account scoped message evidence. Open Scam Advisor from the message security panel to create a private case for review. Public users can upload an EML file through the checker below.
Questions about this check
Does a DKIM or SPF pass prove the email is genuine?
Authentication helps establish which domain sent or signed a message. It does not prove that the request is honest or that a mailbox has not been compromised.
Can I upload an attachment?
You can submit supported documents or the original EML. The result reports the malware signature scan and available text extraction, including any checks that failed.

