IsThisAScam
Strona GłównaBlogCennikO NasHistoryAPI
Upgrade
PL
Sign in
Sign in
IsThisAScam

Independent scam & phishing analysis. Free for individuals. APIs for developers.

Operated by Zeplik, Inc.
Produkt
  • Home
  • Blog
  • Pricing
  • O Nas
  • History
Resources
  • Dokumentacja API
  • Phishing brief
  • Romance scams
  • Tech support
Informacje Prawne
  • Polityka Prywatności
  • Regulamin
  • product@zeplik.com

© 2026 Zeplik, Inc. Wszelkie prawa zastrzeżone.

Built for the calm, the cautious, and the careful.

Home/Blog/Guides
Guides

VirusTotal for Emails: How to Check Messages

IsThisAScam Research TeamJune 12, 20263 min read
Contents
  1. What VirusTotal Does Well
  2. File Scanning
  3. URL Scanning
  4. Hash Lookup
  5. What VirusTotal Cannot Do for Emails
  6. It Cannot Analyze Email Content
  7. It Cannot Check Email Authentication
  8. It Cannot Detect Social Engineering
  9. It Cannot Detect AI-Generated Phishing
  10. How to Use VirusTotal for Email-Related Checks
  11. Step 1: Check Suspicious Attachments
  12. Step 2: Check Links in the Email
  13. Step 3: Check the Sender's Domain
  14. Limitations of VirusTotal's Detection
  15. The Better Alternative for Email Analysis

VirusTotal is one of the most respected security tools on the internet. Owned by Google (via Chronicle/Mandiant), it scans files and URLs against 70+ security vendor engines simultaneously. But when it comes to email analysis, VirusTotal has significant limitations that most users do not realize. This guide explains what VirusTotal can and cannot do for email security, and when to use a more specialized tool.

Need to check an email now? IsThisAScam.to is purpose-built for email analysis — paste the full message for comprehensive 6-layer detection.

What VirusTotal Does Well

File Scanning

Upload any file (up to 650MB) and VirusTotal scans it against 70+ antivirus engines. If an email attachment seems suspicious — a PDF, Word document, Excel file, or executable — uploading it to VirusTotal is an excellent first step. If multiple engines flag the file, it is almost certainly malicious.

URL Scanning

Paste a URL and VirusTotal checks it against 90+ URL scanning engines and blacklists. If a link in an email looks suspicious, this tells you whether any security vendor has flagged it.

Hash Lookup

For advanced users, you can check a file's hash (MD5, SHA-256) without uploading the file itself. This is useful for checking known malware signatures quickly.

Think it might be a scam?

Paste it here for a free, instant verdict.

Free · No signup required · Cmd+Enter to scan

What VirusTotal Cannot Do for Emails

It Cannot Analyze Email Content

VirusTotal has no interface for pasting an email body and analyzing the text for phishing indicators, social engineering patterns, or scam characteristics. You can check individual links from the email, but you cannot submit "This email says my Amazon account is suspended and I need to verify my identity" for analysis.

It Cannot Check Email Authentication

VirusTotal does not check SPF, DKIM, or DMARC results. These authentication checks — which reveal whether the email actually came from the claimed sender — are among the most powerful indicators of phishing. See our email header guide for how to check these manually.

It Cannot Detect Social Engineering

An email that contains no malicious links or attachments but uses social engineering to trick you into calling a fake phone number, replying with sensitive information, or making a wire transfer — VirusTotal cannot evaluate this. Many modern scams are "clean" from a URL/malware perspective but dangerous from a social engineering perspective.

It Cannot Detect AI-Generated Phishing

AI-generated phishing emails are grammatically perfect and may contain only legitimate URLs (like a real bank's website) — the scam is in getting you to call a fake phone number mentioned in the text. VirusTotal's URL and file scanning cannot identify these.

How to Use VirusTotal for Email-Related Checks

Despite its limitations for full email analysis, VirusTotal is valuable for specific email-related tasks:

Step 1: Check Suspicious Attachments

  1. Do NOT open the attachment
  2. Save it to your computer (without opening)
  3. Go to virustotal.com
  4. Click "Choose file" and upload the attachment
  5. Wait for the scan results (usually 30-60 seconds)
  6. If any engines detect malware, do not open the file

Note: be cautious about uploading sensitive business documents — VirusTotal shares submitted files with its security partners.

Step 2: Check Links in the Email

  1. Hover over the link to see the full URL (do not click)
  2. Copy the URL
  3. Go to virustotal.com > URL tab
  4. Paste and scan
  5. If multiple engines flag it, the URL is malicious

Step 3: Check the Sender's Domain

  1. Extract the domain from the sender's email address (the part after @)
  2. Search this domain on VirusTotal
  3. Check if it has been associated with malicious activity

Limitations of VirusTotal's Detection

  • Zero-day threats: Brand new malware or phishing URLs may not be in any vendor's database yet. VirusTotal showing 0 detections does not guarantee safety.
  • Evasive techniques: Sophisticated phishing sites may detect VirusTotal's scanning bots and show benign content to them while serving phishing pages to real users.
  • Geographic cloaking: Some scam sites only serve malicious content to visitors from specific countries. VirusTotal's scanners may not trigger the malicious payload.

The Better Alternative for Email Analysis

IsThisAScam was built specifically for the email analysis use case that VirusTotal does not cover. Its 6-layer detection engine evaluates:

  1. All links in the email — checking domain age, SSL, and reputation (similar to VirusTotal, but in context)
  2. Email content patterns — identifying urgency triggers, social engineering language, and known scam scripts
  3. Sender analysis — evaluating the sender domain's reputation and configuration
  4. AI content detection — flagging AI-generated phishing text
  5. Threat database matching — cross-referencing the entire email against known scam templates
  6. Behavioral indicators — assessing whether the email fits known scam playbooks

Use VirusTotal for file scanning and individual URL checks. Use IsThisAScam for comprehensive email analysis.

For more email security options, see best email security tools and free phishing check tools.

Received something suspicious? Check it now for free →

Share this article
XLinkedInFacebookWhatsApp
VirusTotalemail securitymalwaretools
Related Articles
Product Updates3 min

Free Phishing Check Tools: Complete List

Security Tips4 min

What is Ransomware? Prevention and Recovery

Security Tips4 min

How to Secure Your Phone Against Scams and Malware

Check any suspicious message

Six detection layers. Instant verdict. Free.

Free · No signup required · Cmd+Enter to scan