Load a suspicious item — attachments and links are sandboxed automatically, and the AI has a recommendation ready before you open it.
Tie this review to an ITSM ticket so it's easy to find later from the Dashboard.
Drop a .eml or .msg file here
or click to browse · max 256MB
or
Forward suspicious emails as an attachment (not inline) to [email protected] — they'll appear in the list below within about a minute. Forwarding as an attachment keeps the original SPF/DKIM results intact; an inline forward only reflects your own mail server's results.
SentinelOne alerts sync automatically via API — no upload needed. Pick one below.
Emails a user asked Trustifi to release from quarantine sync automatically — no upload needed. Pick one below to review before it's released or rejected.
Quick, one-off sandbox check for a single link — no case is created, just a result. Resolved in an isolated sandboxed browser, redirects followed, screenshot captured.
Quick, one-off sandbox check for a single file — no case is created, just a result.
Drop a file here
or click to browse · max 256MB
Quick, one-off reputation lookup for a file hash — no case is created, just a result. Accepts MD5, SHA-1, or SHA-256.
Quick, one-off reputation and geolocation lookup for an IPv4 or IPv6 address — no case is created, just a result.
Quick, one-off lookup for a bare domain — known-bad/lookalike/age check, real DNS records (A/MX/NS/SPF/DMARC), and registrar/registrant detail from RDAP or WHOIS. No case is created, just a result.