Skip to content
Klarinbox

Every tool, and what it does not do

The complete list, with each tool's limit written in plain words. Behind all these pages, the same workshop: a file dropped on one opens on all of them.

Open and read

Open a .msg file

Drop the file: the message is shown with its sender, recipients, date, body and attachments. It is read in this tab and sent nowhere.

  • The message header: sender, recipients, copies, date, subject, importance.
  • The body as it was written: HTML, plain text, or RTF, the format Outlook keeps for formatted messages.
  • The attachments, with their names and sizes, to save one by one or all together.
  • A message attached to a message (a .msg inside a .msg) opens in turn, and the screen says at which level it sits.
  • Images attached to the body (cid:) are shown; images hosted elsewhere are not loaded.

What it does not do: An encrypted or signed message (S/MIME) is not decrypted, and its signature is not verified. Klarinbox shows what the file contains; it does not certify that a message is authentic. A whole mailbox (.pst, .ost) is not read here.

Open an .eml file

Drop an .eml or .emlx: the message is shown with its header, body and attachments, in the right script, whatever its encoding. The file stays in this tab.

  • The header: sender, recipients, copies, date, subject, with accented names and non-Latin scripts decoded.
  • Every part of the message: HTML, text, and both when the sender sent both.
  • The character set declared by each part: UTF-8, ISO-8859-1, Windows-1252 and the others.
  • Attachments, an .eml forwarded as an attachment, a winmail.dat: each one opens in turn.
  • Apple Mail's .emlx, read like an .eml.

What it does not do: An encrypted message (S/MIME, PGP) is not decrypted, and a signature is not verified. An mbox mailbox, which holds thousands of messages one after another in a single file, is not read here.

Open a winmail.dat

A winmail.dat is an envelope made by Outlook, holding the attachments and formatting of a message. Drop it: the files inside come out with their names, ready to save.

  • The attachments inside the envelope, with their original names and sizes.
  • The message body when the envelope carries it, as RTF or HTML.
  • An Outlook message attached inside the envelope, opened in turn.
  • A winmail.dat still inside its email: drop the whole .eml or .msg, and the envelope is opened on the way.

What it does not do: An envelope that only carries the message formatting, with no attachment, gives back only the text. The Outlook setting that produces these files is changed on the sender's side, not here.

Open a PST file

Drop the mailbox: its folders and messages are listed, search covers subjects, senders and bodies, and each message opens, can be extracted or turned into a PDF. The file is read piece by piece, never loaded whole.

  • The folder tree and the list of messages, by date, with sender, subject and attachments.
  • Search in subjects, senders and bodies, and filters: period, sender, folder, messages with attachments.
  • Messages marked personal or private, and those in "Personal" folders, are set aside by default; including them is an explicit choice.
  • Each message opens like a .msg: body, attachments, attached messages, headers. It can be saved as PDF or added to an exhibit file.
  • Files of several gigabytes are read piece by piece: they are never loaded whole into the tab's memory.

What it does not do: A password-protected PST is not opened: the protection is not bypassed. Klarinbox reads what the file contains; it does not repair a damaged mailbox or recover deleted messages.

Open an mbox mailbox

Drop the .mbox file: its messages are listed, sorted by label for a Gmail export, and each one opens, can be extracted or turned into a PDF. The file is read piece by piece, never loaded whole.

  • Gmail labels become folders, nested labels included; a message with several labels appears under each.
  • Search in subjects, senders and bodies, and filters: period, sender, label, attachments.
  • Personal messages (a "Personal" label, a subject that says so) are set aside by default, and including them is a choice.
  • Each message opens like an .eml: body, attachments, attached messages, headers; it can be saved as PDF or added to an exhibit file.
  • Files of several gigabytes are read piece by piece, never loaded whole into the tab.

What it does not do: Klarinbox reads what the file contains: it does not connect to Gmail and downloads nothing. An encrypted message is not decrypted.

Extract

Extract attachments

Drop one or more messages: their attachments come out in an archive sorted by message, including those sleeping inside an attached message or a winmail.dat.

  • The attachments of each dropped message, in one folder per message, named after its date, sender and subject.
  • Attached messages (a .msg inside a .msg, a forwarded .eml) and winmail.dat files, opened in turn: the screen says at which level each attachment sits.
  • A CSV index: message, attachment name, size, SHA-256 fingerprint.
  • File names kept as sent, and told apart when two attachments share a name.

What it does not do: An attachment is never opened by the page: it is extracted as it is, neither run nor converted. Whole mailboxes (.pst, .ost, .mbox) are not read here.

Check

Read email headers

The headers of a message say which servers it went through, at what time, and what the receiving server checked. Drop the message: they are put back in order and explained line by line.

  • The route (Received) put back in order, from the first server to the last, with times brought to a single time zone and the time spent at each step.
  • The authentication results already recorded by the receiving server (Authentication-Results): SPF, DKIM, DMARC.
  • The message ID, the sending software, the reply-to and return addresses.
  • Inconsistencies, stated as observations with their possible innocent cause: a date later than receipt, times going backwards, an ID from a domain other than the sender's.
  • Every raw header, to copy as it is.

What it does not do: Nothing is checked live: the DKIM signature is not recomputed and no DNS query is made, since it would leave the tab. The results shown are those the receiving server recorded. Klarinbox says what it observes; it never says a message is fake or authentic.

Produce

Convert an email to PDF

Drop one or more messages: each becomes a PDF with selectable text, its header, its body, the list of its attachments and, as an appendix, a record of the file it came from.

  • One PDF per message, or a single PDF with the messages one after another, each starting on a new page.
  • Text stays text: it can be selected, copied and searched. Fonts are embedded; Arabic, Hebrew, Russian, Chinese, Japanese and emojis are displayed.
  • The message's images (logo, signature, screenshots) are kept; remote images are not loaded and their address is written in their place.
  • A production record as an appendix: name, size and SHA-256 fingerprint of the source file, attachments and their fingerprints, full headers, date of production.
  • PDF/A as an option for archiving, which can also carry the original file.

What it does not do: The layout is made for correspondence: a newsletter with columns and background images is rendered simplified, and the PDF says so. The record describes the source file; it does not attest that a message is authentic.

Produce exhibits and their list

Drop the messages to file: they are sorted by date and numbered, each becomes a PDF with its number at the top of every page, and the exhibit list is ready in Word and PDF.

  • Messages sorted by date, numbered from the number you choose; order, numbers and descriptions can be changed before producing.
  • One PDF per exhibit, named "Exhibit 12 - date - subject", with "Exhibit 12" at the top of every page and page numbers of its own.
  • The production record as an appendix to each exhibit, which ties the PDF to its original file through its SHA-256 fingerprint.
  • The exhibit list in Word, to adjust it, and in PDF: number, date, type and description of each exhibit.
  • Everything saved as one archive, or exhibit by exhibit.

What it does not do: Klarinbox formats what the dropped files contain; it says nothing about their authenticity or admissibility, which remain to be assessed. To mask personal data before sharing an exhibit, use Klarmask.

Chats

Read a WhatsApp chat

Export the chat from the phone, then drop the file here: it is shown as on the screen, as bubbles, with its photos and voice notes. Pick a period or messages, and the extract says what it leaves out.

  • Exports from iPhone or Android, in any phone language, in 12 or 24-hour time: the screen says how the date was read, and you can correct it if it is ambiguous.
  • Messages as bubbles, yours on the right; photos shown, voice notes and videos playable, other files ready to save.
  • An extract by period or message by message, with the context you want around it: what is left out is counted and written in its place.
  • Inconsistencies in the export (times going backwards, lines in another format, media mentioned but missing) are stated as observations, with their possible innocent cause.

What it does not do: Klarinbox reads the exported file; it does not connect to WhatsApp. An export is plain text: on its own it does not prove the messages were not altered, and Klarinbox does not attest it. Times are those of the phone that exported.

WhatsApp chat to PDF

Drop the export, pick the period or the messages, and the PDF is ready: as bubbles like on the phone or as a dated table, with the photos, omissions written in their place and a record that ties it to its file.

  • Two layouts: bubbles like on the phone, your messages on the right, or a table of date, time, author, text.
  • The extract you choose, with left-out messages counted and written in their place: "214 messages left out from 3 to 9 March".
  • Photos as thumbnails, other media cited by name and fingerprint.
  • "Exhibit 12" at the top of pages if you want, and a production record: source file and SHA-256 fingerprint, how the date was read, participants, omissions, observations.
  • PDF/A as an option for archiving, which can carry the original export.

What it does not do: Klarinbox formats what the export contains; it says nothing about its authenticity or admissibility. The record describes the source file; it does not certify that the messages were not altered. Times are those of the phone that exported.