Email Threat Analysis: Rapid .eml Triage Commands for Analysts
1/11/2026Shell commands to run when triaging a downloaded .eml file, with explanations of what each command and flag does.
playbooksemailincident-responseforensics
when a problem repeats, i script it. when the script is useful, it lands here with setup, commands, and troubleshooting.
Shell commands to run when triaging a downloaded .eml file, with explanations of what each command and flag does.
Turn jumbled headers into a readable hop trail with SPF/DKIM/DMARC snapshots — evidence only.
Tiny Python CLI to quickly check SPF, DMARC, MTA-STS, TLS-RPT, and optional DKIM selectors.