Skip to content

← Email security

Email header analyzer

Paste the raw headers from a suspicious email. We'll trace every server it passed through, read the SPF / DKIM / DMARC results, and flag the tells that give away a forgery — all in your browser.

Paste raw email headers

Runs entirely in your browser — nothing is uploaded.

Gmail: open the message → ⋮ → Show original. Outlook: File → Properties → Internet headers. Apple Mail: View → Message → All Headers.

How to read the results

  • SPF / DKIM / DMARC are the three checks the receiving server runs to prove a message really came from where it claims. A fail on any of them is the single strongest signal that an email is forged.
  • The delivery path lists every mail server the message touched, oldest first. A legitimate message usually shows a short, sensible chain; a surprise relay in an unexpected country is worth a second look.
  • Identity headers show who the message says it's from. When the visible From and the envelope Return-Path disagree — or the display name hides a different address — that's a classic phishing trick.

Want this checked automatically for every message? Publishing your own SPF, DKIM, and DMARC records is what lets other inboxes reject forgeries that impersonate your domain. Scan your domain free →