Skip to main content

Email Intel

Status Python AWS Last Commit

Email header analysis tool + organizational infrastructure profiler with a web dashboard. Paste raw email headers and get IP geolocation, sending stack fingerprinting, org profiling, and change detection across 147 organizations.

What It Does

  • Header Analysis: Parse raw email headers to extract originating IP, relay chain, SPF/DKIM/DMARC status, and sending software
  • IP Geolocation: Resolve originating IPs via ip-api.com (default) or MaxMind GeoLite2
  • Org Profiling: Fingerprint sending infrastructure: ESP (Salesforce/HubSpot/Mailchimp/Marketo/etc.), CDN, mail server vendor, authentication posture
  • Change Detection: Rules-based classifier flags positive, negative, or neutral infrastructure changes when an org's stack changes between scans
  • Plocamium Bridge: Optional integration to push org signals into the Plocamium content engine pipeline
  • Web Dashboard: Local HTML dashboard at localhost:8888 showing 147 profiled orgs, change feed, and scan history

Architecture

CLI (Click + Rich)
    ↓
parser.py      : Raw header → structured EmailAnalysis
geo.py         : IP → GeoResult (ip-api or MaxMind)
org_profiler.py: Domain → OrgStack (ESP, CDN, MX, DMARC)
org_store.py   : SQLite persistence of org profiles + scan history
org_classifier.py: Change classification (positive/negative/neutral)
reporter.py    : Rich terminal output + JSON/CSV export
dashboard.py   : Stdlib HTTP server for the web dashboard
plocamium_bridge.py: Optional signal push to Plocamium

Install

pipx install email-header-intel            # or: uv tool install email-header-intel
pipx install 'email-header-intel[gmail]'   # with Gmail API support
pipx install 'email-header-intel[maxmind]' # with MaxMind GeoLite2 support

The PyPI package is email-header-intel (PyPI reserves email-intel as too similar to another project); the command is still email-intel.

</code></pre>
<h2><a href="#user-content-usage" aria-hidden="true" class="anchor" id="user-content-usage"></a>Usage</h2>
<pre><code class="language-bash"># Single header analysis
email-intel analyze --headers "$(pbpaste)"

# Scan an org by domain
email-intel scan example.com

# Batch scan from file
email-intel batch orgs.txt

# Start web dashboard
email-intel dashboard --port 8888

# Export results
email-intel analyze --headers "..." --format json --output result.json

Stack

  • Language: Python 3.12
  • CLI: Click + Rich (terminal output)
  • Geo: ip-api.com (free tier) or MaxMind GeoLite2 DB
  • Storage: SQLite (org profiles, scan history, change log)
  • Dashboard: Flask + vanilla JS (local only)
  • Tests: pytest, 105 tests

Setup

pip install -e .
cp config.example.yaml config.yaml   # configure geo provider, Plocamium token
email-intel --help

Metadata

Release files for email-header-intel 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for email-header-intel 1.0.0
File Size Uploaded
email_header_intel-1.0.0.tar.gz 47.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for email-header-intel 1.0.0
File Interpreter ABI Platform
email_header_intel-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 90.0 kB

Release files / email_header_intel-1.0.0.tar.gz

Download URL email_header_intel-1.0.0.tar.gz
Size 47.4 kB
Tags Source
SHA-256 checksum
How to use checksums
eca99a24bee0accda165d66ae23d61ceb0b3d75b48c26cbd291edb28a074c821
BLAKE2b-256 checksum
How to use checksums
1010ed17bcee4ad6bd3f292f121703c35a9356e5e865796917931b2218646b1d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / email_header_intel-1.0.0-py3-none-any.whl

Download URL email_header_intel-1.0.0-py3-none-any.whl
Size 42.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c20ea89ffba4abdc934ff5af40ea6e2b9e48d1cab4143c9201ee5aa1c4f08546
BLAKE2b-256 checksum
How to use checksums
a88495167b448b56297ded4c1b9557f3145121cc127908f1675b310b31de5e6d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page