Email Intel
Email header analysis tool + organizational infrastructure profiler with a web dashboard. Paste raw email headers and get IP geolocation, sending stack fingerprinting, org profiling, and change detection across 147 organizations.
What It Does
- Header Analysis: Parse raw email headers to extract originating IP, relay chain, SPF/DKIM/DMARC status, and sending software
- IP Geolocation: Resolve originating IPs via ip-api.com (default) or MaxMind GeoLite2
- Org Profiling: Fingerprint sending infrastructure: ESP (Salesforce/HubSpot/Mailchimp/Marketo/etc.), CDN, mail server vendor, authentication posture
- Change Detection: Rules-based classifier flags positive, negative, or neutral infrastructure changes when an org's stack changes between scans
- Plocamium Bridge: Optional integration to push org signals into the Plocamium content engine pipeline
- Web Dashboard: Local HTML dashboard at
localhost:8888showing 147 profiled orgs, change feed, and scan history
Architecture
CLI (Click + Rich)
↓
parser.py : Raw header → structured EmailAnalysis
geo.py : IP → GeoResult (ip-api or MaxMind)
org_profiler.py: Domain → OrgStack (ESP, CDN, MX, DMARC)
org_store.py : SQLite persistence of org profiles + scan history
org_classifier.py: Change classification (positive/negative/neutral)
reporter.py : Rich terminal output + JSON/CSV export
dashboard.py : Stdlib HTTP server for the web dashboard
plocamium_bridge.py: Optional signal push to Plocamium
Install
pipx install email-header-intel # or: uv tool install email-header-intel
pipx install 'email-header-intel[gmail]' # with Gmail API support
pipx install 'email-header-intel[maxmind]' # with MaxMind GeoLite2 support
The PyPI package is email-header-intel (PyPI reserves email-intel as
too similar to another project); the command is still email-intel.
</code></pre>
<h2><a href="#user-content-usage" aria-hidden="true" class="anchor" id="user-content-usage"></a>Usage</h2>
<pre><code class="language-bash"># Single header analysis
email-intel analyze --headers "$(pbpaste)"
# Scan an org by domain
email-intel scan example.com
# Batch scan from file
email-intel batch orgs.txt
# Start web dashboard
email-intel dashboard --port 8888
# Export results
email-intel analyze --headers "..." --format json --output result.json
Stack
- Language: Python 3.12
- CLI: Click + Rich (terminal output)
- Geo: ip-api.com (free tier) or MaxMind GeoLite2 DB
- Storage: SQLite (org profiles, scan history, change log)
- Dashboard: Flask + vanilla JS (local only)
- Tests: pytest, 105 tests
Setup
pip install -e .
cp config.example.yaml config.yaml # configure geo provider, Plocamium token
email-intel --help
Metadata
Release files for email-header-intel 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| email_header_intel-1.0.0.tar.gz | 47.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| email_header_intel-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 90.0 kB
Release files / email_header_intel-1.0.0.tar.gz
| Download URL | email_header_intel-1.0.0.tar.gz |
|---|---|
| Size | 47.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
eca99a24bee0accda165d66ae23d61ceb0b3d75b48c26cbd291edb28a074c821
|
|
BLAKE2b-256 checksum How to use checksums |
1010ed17bcee4ad6bd3f292f121703c35a9356e5e865796917931b2218646b1d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / email_header_intel-1.0.0-py3-none-any.whl
| Download URL | email_header_intel-1.0.0-py3-none-any.whl |
|---|---|
| Size | 42.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c20ea89ffba4abdc934ff5af40ea6e2b9e48d1cab4143c9201ee5aa1c4f08546
|
|
BLAKE2b-256 checksum How to use checksums |
a88495167b448b56297ded4c1b9557f3145121cc127908f1675b310b31de5e6d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|