Quoted-Printable Decoder
Decode quoted-printable email bodies (=3D, =C3=A5, soft line breaks) to read the real text and links of a suspicious message — or encode text.
How to use
- Open the message source (“Show original” / “View source”) and copy the body part marked Content-Transfer-Encoding: quoted-printable.
- Paste it here and read the decoded text or HTML.
- Links hidden in href=3D"…" become readable — check the real destination before anyone clicks.
Steps
Output
Why email uses quoted-printable
Email was designed for short lines of 7-bit ASCII. Quoted-printable (RFC 2045) keeps mostly-ASCII text readable while making it safe to send: any byte that is not plain printable ASCII — and the = sign itself — is written as = followed by two hex digits, and lines longer than 76 characters are broken with a trailing “soft” =. UTF-8 characters take several escapes, so ä appears as =C3=A4.
Reading suspicious messages
In the raw source of a phishing email the HTML is full of =3D and broken lines, which makes the real link target hard to read — and that is sometimes the point. Decoding joins the soft line breaks and restores every =, so href="…" shows the exact destination, including look-alike domains that are flagged automatically. Copy the decoded links into a ticket in defanged form with the IOC Extractor.
Body versus headers
Quoted-printable applies to message bodies, declared with Content-Transfer-Encoding: quoted-printable. Subject and From headers use a related but different format, encoded words such as =?UTF-8?Q?…?= or =?UTF-8?B?…?= (RFC 2047) — use the “MIME encoded-word decode” step for those. Parts declared as charset=windows-1252 or iso-8859-1 need “Windows-1252 / Latin-1 → text” after decoding. Base64-encoded bodies (Content-Transfer-Encoding: base64) need the Base64 decode step instead.
Common questions
What does =3D mean in an email?
It is quoted-printable for the = sign (byte 0x3D). Because = starts every escape, a literal = must itself be encoded, so HTML attributes appear as href=3D"…".
Why do lines in the source end with =?
That is a soft line break. Quoted-printable lines are limited to 76 characters, so long lines are split with a trailing = that disappears when decoded.
Is it safe to paste a phishing email here?
Yes. The decoded HTML is shown as text and never rendered, so no images, trackers or scripts load, and the page is locked so it cannot connect anywhere.
Known limitations
- The result is read as UTF-8. For parts declared as charset=iso-8859-1 or windows-1252, use the “Quoted-printable (Latin-1) → text” preset.
- Paste one MIME part at a time; multipart boundaries and headers are not parsed.
- HTML is shown as source code, never rendered — so nothing in the email can load or run.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- RFC 2045 §6.7 — quoted-printable (opens in a new tab)
- RFC 2047 — encoded words in headers (opens in a new tab)
- RFC 2046 — MIME multipart messages (opens in a new tab)