All workflows
Gmail logoIPWHOIS.io logoRDAP logoSlack logo

See what your incoming mail links to

Lists the hosts new mail links to, leaves out the ones you expect, adds what the public registry holds on each, and posts it to Slack.

On new email in Gmail4 apps6 steps

Apps it connects

Authenticate each one once and the workflow is ready to run.

What it does

The integration steps this workflow runs, in the order it first runs them.

  1. 1GmailNew email trigger
  2. 2GmailList emails
  3. 3IPWHOIS.ioGet ip network
  4. 4RDAPLookup domain
  5. 5SlackSend message
  6. 6GmailAdd label to message

How it works

Everything the template sets up, and what to fill in before the first run.

Mail that wants something from you almost always wants you to click. This workflow reads the mail that arrives, pulls the web addresses out of the message text, and posts one Slack note per message listing the hosts those links point to - but only the hosts that are not on the list of domains you already expect.

That list is the whole point. Put your own domains and your suppliers' into 'expectedDomains' and the ordinary traffic goes quiet, so what reaches Slack is the mail linking somewhere you did not expect.

For each of those hosts it records:

- What the public domain registry holds: when the name was registered, how many days ago that is, and the registrar of record. A name registered days before it turned up in your mail is worth a person's attention; a name registered years ago is worth knowing too. - When the link names an address rather than a name, who runs that address - the provider, the autonomous system and the country - from the public address registry. - Whether the link was written over plain http, whether the name is written in punycode (the 'xn--' form used to build lookalikes), and whether it is on the sender's own domain.

It reports and it does not conclude. No step here says a link is worth opening or not worth opening, because nothing available to it could support that, and a wrong reassurance is worse than no answer at all. Nothing found is not the same as nothing there.

It never visits any of these addresses. Only the host part of a link is used - for the lookups and in the report - and the rest is deliberately dropped, because the path of a link in unsolicited mail routinely carries a code identifying the person it was sent to, and a Slack channel is read by people who were not written to. Before anything is posted, the report is checked for a web address and one is taken out rather than passed on.

Two limits worth knowing. Links are read from the plain-text part of a message, which nearly all mail carries alongside its formatted version; a message that has only formatted text will show no links, and the run log says so rather than the report saying the message had none. And each message is labelled once it has been read, with the Gmail search excluding that label, so nothing is reported twice - the label goes on after the report, so an interrupted run repeats a message rather than skipping it.

To set it up, put a Gmail search naming the mail to read into 'mailSearch', the Slack channel into 'slackChannelId', and the domains you already expect into 'expectedDomains'. 'checkedLabel', 'maxMessagesPerRun' and 'maxHostsPerMessage' have working defaults - ten messages a run and ten reported hosts a message. Naming a sender on the trigger step narrows what wakes it; left empty, any new mail wakes it and the search decides what is read.

gmailslackemaillinksdomainsrdapevent driven

Start from a workflow that already works.

Add "See what your incoming mail links to" to your workspace, connect its apps, and make it yours. No credit card required.

Free plan available · No credit card required