/v1/eml/analyzeeml:analyzeAnalyser un e-mail (.eml)
Verdict expliqué, authentification SPF/DKIM/DMARC et alignement, cohérence des identités, inventaire des liens, observables défangés, routage Received et pièces jointes (MD5, SHA-1, SHA-256). Le fichier est analysé en mémoire et n’est jamais conservé.
Corps de la requête
| Content-Type | Description |
|---|---|
| message/rfc822 | Le fichier .eml brut (recommandé). |
| multipart/form-data | Champ file (+ champs include, lang). |
| application/json | { "eml": "…" } (texte) ou { "eml_base64": "…" }, + filename, include, lang. |
Paramètres
| Paramètre | Type | Description |
|---|---|---|
| include | string · query | form | JSON | Sections optionnelles, séparées par des virgules : headers, body, report. |
| lang | fr | en | Langue des libellés de signaux et du rapport (défaut : fr). |
| filename | string | Nom du fichier, renvoyé dans file.name. |
curl -X POST "https://api.forenshield.com/v1/eml/analyze?include=report" \
-H "Authorization: Bearer $FORENSHIELD_API_KEY" \
-H "Content-Type: message/rfc822" \
--data-binary @suspect.emlVariante JSON (base64)
curl -X POST "https://api.forenshield.com/v1/eml/analyze" \
-H "Authorization: Bearer $FORENSHIELD_API_KEY" \
-H "Content-Type: application/json" \
-d "{\"eml_base64\": \"$(base64 -w0 suspect.eml)\", \"include\": [\"headers\"], \"lang\": \"en\"}"Exemple de réponse
200 OK · application/json
{
"id": "req_7f3a91c2d8e64b05a1c9e2f4",
"object": "eml.analysis",
"api_version": "2026-09-30",
"created_at": "2026-09-30T09:12:04.512Z",
"lang": "fr",
"file": {
"name": "demo-hameconnage.eml",
"size": 2198,
"md5": "66c6044c7b1be88044336e3ad2dcc22e",
"sha1": "9124751a51cf0d51eba352560d1e7f5ea90b8110",
"sha256": "a92d9083123c1903e233891f5a14b927a5a5768110d913a8d63e1bf76ae1447f"
},
"verdict": {
"score": 100,
"level": "critical",
"label": "Très suspect",
"signals": [
{
"id": "double-ext-0-releve-compte.pdf.exe",
"label": "Double extension trompeuse : releve-compte.pdf.exe.",
"points": 35,
"severity": "danger"
},
{
"id": "spf-fail",
"label": "Échec SPF : l'expéditeur n'est pas autorisé à envoyer depuis ce domaine.",
"points": 25,
"severity": "danger"
},
{
"id": "dmarc-fail",
"label": "Échec de la politique DMARC du domaine affiché.",
"points": 20,
"severity": "danger"
},
{
"id": "display-name",
"label": "Le nom affiché contient une autre adresse ([email protected]) que l’expéditeur réel : usurpation probable.",
"points": 20,
"severity": "danger"
}
]
},
"message": {
"subject": "Urgent : votre compte sera suspendu sous 24 h",
"date": "2026-09-26T07:12:00.000Z",
"message_id": "<[email protected]>",
"mailer": null,
"from": {
"name": "[email protected]",
"address": "[email protected]"
},
"reply_to": {
"name": null,
"address": "[email protected]"
},
"return_path": "[email protected]",
"to": [
{
"name": null,
"address": "[email protected]"
}
],
"cc": []
},
"authentication": {
"receiver": "mx.destinataire.example",
"arc": false,
"spf": {
"result": "fail",
"domain": "mailer-exemple.test",
"aligned": false
},
"dkim": {
"result": "none",
"domain": null,
"aligned": false,
"signatures": []
},
"dmarc": {
"result": "fail",
"policy": "reject",
"header_from": "banque-exemp1e.com"
},
"identities": [
{
"role": "from",
"address": "[email protected]",
"domain": "banque-exemp1e.com",
"aligned": true
},
{
"role": "replyTo",
"address": "[email protected]",
"domain": "recuperation-compte.test",
"aligned": false
},
{
"role": "returnPath",
"address": "[email protected]",
"domain": "mailer-exemple.test",
"aligned": false
},
{
"role": "mailfrom",
"address": "mailer-exemple.test",
"domain": "mailer-exemple.test",
"aligned": false
},
{
"role": "messageId",
"address": "[email protected]",
"domain": "banque-exemp1e.com",
"aligned": true
}
]
},
"links": [
{
"url": "https://banque-exemp1e.com/verification",
"url_defanged": "hxxps[://]banque-exemp1e[.]com/verification",
"host": "banque-exemp1e.com",
"base_domain": "banque-exemp1e.com",
"scheme": "https",
"sources": [
"href",
"text"
],
"displayed_texts": [
"https://www.banque-exemple.fr/espace-client"
],
"hidden_destination": null,
"flags": [
"deceptive"
],
"risk": "danger",
"occurrences": 2
},
{
"url": "https://recuperation-compte.test/collect",
"url_defanged": "hxxps[://]recuperation-compte[.]test/collect",
"host": "recuperation-compte.test",
"base_domain": "recuperation-compte.test",
"scheme": "https",
"sources": [
"form"
],
"displayed_texts": [],
"hidden_destination": null,
"flags": [
"form",
"external"
],
"risk": "danger",
"occurrences": 1
}
],
"observables": {
"urls": [
{
"value": "https://banque-exemp1e.com/verification",
"defanged": "hxxps[://]banque-exemp1e[.]com/verification",
"context": [
"href",
"text"
],
"risk": "danger"
},
{
"value": "https://recuperation-compte.test/collect",
"defanged": "hxxps[://]recuperation-compte[.]test/collect",
"context": [
"form"
],
"risk": "danger"
}
],
"domains": [
{
"value": "banque-exemp1e.com",
"defanged": "banque-exemp1e[.]com",
"context": [
"link",
"from"
],
"risk": "none"
},
{
"value": "recuperation-compte.test",
"defanged": "recuperation-compte[.]test",
"context": [
"link",
"replyTo"
],
"risk": "none"
}
],
"ips": [
{
"value": "198.51.100.23",
"defanged": "198[.]51[.]100[.]23",
"context": [
"origin"
],
"risk": "none"
}
],
"emails": [
{
"value": "[email protected]",
"defanged": "alerte[@]banque-exemp1e[.]com",
"context": [
"from",
"content"
],
"risk": "none"
},
{
"value": "[email protected]",
"defanged": "support[@]recuperation-compte[.]test",
"context": [
"replyTo",
"content"
],
"risk": "none"
}
],
"hashes": [
{
"value": "4656fc54d9b6b16f3fca03f6564348f15afea6af886ca04daaac3f080a095d10",
"algorithm": "sha256",
"file": "releve-compte.pdf.exe",
"risk": "danger"
},
{
"value": "d10d4660e6b37078cac4d083de2496fb0796aa94",
"algorithm": "sha1",
"file": "releve-compte.pdf.exe",
"risk": "danger"
}
],
"total": 21
},
"routing": {
"origin_ip": "198.51.100.23",
"hop_count": 2,
"total_seconds": null,
"anomalies": 0,
"hops": [
{
"index": 1,
"from_host": "192.168.1.20",
"from_reverse_dns": null,
"ip": "10.0.0.8",
"ip_public": false,
"by_host": "relay.mailer-exemple.test",
"protocol": null,
"tls": false,
"date": null,
"delay_seconds": null,
"anomaly": null
},
{
"index": 2,
"from_host": "relay.mailer-exemple.test",
"from_reverse_dns": "relay.mailer-exemple.test",
"ip": "198.51.100.23",
"ip_public": true,
"by_host": "mx.destinataire.example",
"protocol": "ESMTPS",
"tls": true,
"date": "2026-09-26T07:12:00.000Z",
"delay_seconds": null,
"anomaly": null
}
]
},
"attachments": [
{
"filename": "releve-compte.pdf.exe",
"content_type": "application/octet-stream",
"size": 50,
"inline": false,
"md5": "c98b22d6321a7f9f894ebed205b78237",
"sha1": "d10d4660e6b37078cac4d083de2496fb0796aa94",
"sha256": "4656fc54d9b6b16f3fca03f6564348f15afea6af886ca04daaac3f080a095d10",
"dangerous": true,
"double_extension": true
}
]
}Réponse réelle pour l’e-mail de démonstration, tableaux abrégés.