Email Harvesting Protection Checker
Test how well your email obfuscation protects against automated harvesting techniques. This tool simulates 7 different harvesting methods — from basic regex scraping to advanced Base64 decoding — and gives your obfuscation a letter grade (A-F) with specific improvement suggestions. Paste your obfuscated email HTML or code, click Check Protection, and see exactly which techniques would extract your email. All free, private, and no signup required.
Test how well your email obfuscation protects against automated harvesting techniques. Paste obfuscated email HTML or text, and the tool simulates 7 different harvesting methods to evaluate your protection level. Get a letter grade (A-F) with specific improvement suggestions. All browser-local, no signup required.
Paste obfuscated email HTML or text above and click Check Protection to test how well it resists harvesting. The tool simulates 7 different harvesting techniques and gives you a letter grade (A-F) with specific improvement suggestions. Try loading an example to see how it works!
Features
7 Harvesting Simulations
Tests email obfuscation against plain text regex scraping, HTML entity decoding, ROT13 decoding, [at]/[dot] pattern detection, JavaScript execution analysis, URL encoding decoding, and Base64 decoding. Covers all common harvesting techniques used by bots.
Letter Grade (A-F) Rating
Get a clear A-F protection grade with a numerical score (0-100) based on how many techniques detected your obfuscated email. A = excellent protection, F = critical vulnerability. See exactly which techniques succeeded and which were blocked.
Actionable Suggestions
Receive specific, actionable recommendations to improve your email obfuscation based on which harvesting techniques succeed. Suggestions are prioritized by severity and tailored to your specific obfuscation weaknesses.
Per-Technique Detection Details
Each harvesting technique shows whether it detected the email, what email it found (if any), and a detailed explanation of how the technique works and why it succeeded or failed against your obfuscation.
Use Cases
Website Contact Page Protection
Test email obfuscation before deploying it on your website contact page. Ensure that the email addresses displayed on your About, Contact, and Support pages are properly protected against common harvesting techniques used by spam bots.
Mailto Link Security
Verify that mailto: links with JavaScript-based obfuscation or HTML entity encoding actually protect email addresses. Test different encoding methods to find the right balance between usability and protection for your mailto links.
Email Template Testing
Test email addresses embedded in HTML email templates before sending campaigns. Some email marketing platforms automatically expose email addresses in ways that bypass your intended obfuscation, making pre-deployment testing essential.
Content Management Security
Check email addresses in CMS content (WordPress, Drupal, Joomla) before publishing. Many CMS platforms store email addresses in plaintext or use weak obfuscation that automated harvesters can easily bypass.
Bot Vulnerability Assessment
Assess your current email obfuscation strategy against a comprehensive battery of harvesting techniques. Identify weak spots in your protection and get specific recommendations for hardening your email display methods.
Security Audit & Compliance
Include email exposure testing as part of your regular security audit workflow. Verify that email addresses across your web properties meet your organization's data protection standards and privacy compliance requirements.
About Email Harvesting Protection
What Is Email Harvesting?
Email harvesting is the automated process of collecting email addresses from websites, HTML pages, and other online sources using software bots called harvesters or spambots. These bots scan web pages for email patterns using techniques like regex matching ([email protected]), HTML entity decoding (@ex), and JavaScript execution. Harvested emails are typically sold to spammers, used for phishing campaigns, or added to mailing lists without consent. Effective email obfuscation is essential for any website that displays email addresses publicly.
How Our Protection Checker Works
The tool simulates 7 common email harvesting techniques against your obfuscated email text. Each technique represents a different method that spambots use to extract email addresses. The tool runs each simulation independently and reports whether the email was detected. Based on the number of successful detections, it calculates a protection score and assigns a letter grade (A-F). Grade A means no harvesting technique detected the email. Grade F means most or all techniques succeeded. The tool also generates specific, actionable suggestions for improving your obfuscation where weaknesses were found.
Understanding the 7 Harvesting Techniques
The checker tests against: 1) Plain Text Scraping - basic regex matching for [email protected] patterns. 2) HTML Entity Decoding- decodes @, ., and named entities. 3) ROT13 Decoding - applies the ROT13 cipher to reveal emails. 4) [at]/[dot] Pattern Detection - replaces common text substitution patterns. 5) JavaScript Execution Analysis - detects JS-based obfuscation like document.write(), fromCharCode(), and split/join concatenation. 6) URL Encoding Decoding - decodes %40 and %2E characters. 7) Base64 Decoding - decodes Base64-encoded strings and checks for email patterns.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. Your email obfuscation text, harvesting simulation results, and protection grades are never uploaded to any server, stored in any database, or transmitted over the network. All processing happens locally on your device. There are no API calls, analytics tracking cookies, or data collection of any kind. This makes it completely safe for testing proprietary obfuscation techniques and sensitive email addresses without exposing them to any third party.