Inspiration
For twenty years, the advice was "look for bad spelling." Language models ended that overnight, and phishing prose is now cleaner than the real thing. But an LLM only rewrites the letter. It can't rewrite the envelope: the headers recording which servers actually carried the message. Nobody reads them, because they look like machine noise.
What it does
Paste a suspicious email's raw source, and it tells you who really sent it. It compares the address you're shown against the one the servers actually used, decodes lookalike domains (xn--pypal-4ve.com turns out to be pаypal.com with a Cyrillic а), checks where every link truly goes, flags files like Invoice.pdf.js, and reads the delivery route for timestamps that run backwards.
The verdict is Forged, Suspicious, Unverified, or Authenticated. Never "safe." You also get plain-language advice, and every finding shows the exact line of the email that proves it.
How we built it
Vanilla JavaScript, HTML, and CSS. No framework, no build step, no dependencies, no backend. js/engine.js is the whole product: an RFC 5322 parser, an RFC 3492 punycode decoder written from the spec, a confusable-folding table, and about thirty deterministic rules. It has no DOM or network dependency, which is why the same file backs both the web page and the test suite. Hosted as static files on GitHub Pages.
Nothing is uploaded, ever. The page loads its files and then makes zero network requests. Pull the Wi-Fi, and it still works. The email's own HTML is never rendered either, since the annotated view is rebuilt from plain text. Hostile markup can't run inside the tool examining it.
I did use Claude Code to assist with the website building aspect.
Challenges we ran into
Not crying wolf was the hard part. The first version flagged any third-party Return-Path, which would have fired on every newsletter and receipt ever sent. It now checks whether anything vouches for the mismatch first. Same story with amazonaws.com, which naively reads as a fake amazon.com.
Then there's where it honestly stops. Business email compromise beats every tool like this one. When someone sends from a mailbox they've stolen, every check passes, because nothing is fake except the person typing. Rather than hide that, we made it one of the built-in examples: all checks green, verdict still Suspicious.
Accomplishments that we're proud of
Two of the six built-in specimens are legitimate mail on purpose. A detector you've only ever seen say "bad" hasn't been shown to work.
84 tests with zero dependencies, and a privacy claim you can verify yourself instead of taking our word for it.
What we learned
The useful unit isn't a score; it's a citation. Our first draft produced a risk percentage, which is unfalsifiable and teaches you nothing. Making every finding open to reveal the header underneath it turned the tool from something you trust into something you can check, and honestly, into something you learn the trick from.
What's next for ReturnPath
Verifying DKIM signatures properly over DNS-over-HTTPS, as an opt-in that clearly says it's about to make a network request. A browser extension that reads the open message directly, which removes the copy-paste step that's the real barrier to anyone actually using this. And extending the confusable table to the full Unicode set.
Log in or sign up for Devpost to join the conversation.