Analyze email headers for spoofing and IP reputation

Starting promptUse this prompt as a starting point to build your workflow.

Build a workflow that accepts raw email headers (paste, attachment, or Send-to-Story). Parse the Received chain to extract originating IPs, look up reputation and geolocation for each, and extract SPF, DKIM, and DMARC authentication results. Summarize whether the message shows spoofing indicators and format the findings. Handle malformed headers, missing auth results, and lookup failures gracefully. Output a readable header analysis with a spoofing verdict.

New to Tines?Sign up free for Tines 3B Explore Edition

What this prompt builds

Extract and evaluate email header IPs and auth results to detect spoofing.

The problem

Spoofed emails pass casual inspection because the giveaways are buried in raw headers most people never read. Manually parsing Received chains and SPF/DKIM/DMARC results is slow and specialized.

Solution and impact

This workflow extracts IPs from email headers, checks their reputation and location, parses authentication headers, and returns a formatted summary. Spoofing indicators surface instantly, giving responders a clear verdict.