Analyze email headers for spoofing and IP reputation
Build a workflow that accepts raw email headers (paste, attachment, or Send-to-Story). Parse the Received chain to extract originating IPs, look up reputation and geolocation for each, and extract SPF, DKIM, and DMARC authentication results. Summarize whether the message shows spoofing indicators and format the findings. Handle malformed headers, missing auth results, and lookup failures gracefully. Output a readable header analysis with a spoofing verdict.
What this prompt builds
Extract and evaluate email header IPs and auth results to detect spoofing.
The problem
Spoofed emails pass casual inspection because the giveaways are buried in raw headers most people never read. Manually parsing Received chains and SPF/DKIM/DMARC results is slow and specialized.
Solution and impact
This workflow extracts IPs from email headers, checks their reputation and location, parses authentication headers, and returns a formatted summary. Spoofing indicators surface instantly, giving responders a clear verdict.