Email header analyzer
Paste the raw headers from a suspicious email. We'll trace every server it passed through, read the SPF / DKIM / DMARC results, and flag the tells that give away a forgery — all in your browser.
Paste raw email headers
Gmail: open the message → ⋮ → Show original. Outlook: File → Properties → Internet headers. Apple Mail: View → Message → All Headers.
How to read the results
- SPF / DKIM / DMARC are the three checks the receiving server runs to prove a message really came from where it claims. A
failon any of them is the single strongest signal that an email is forged. - The delivery path lists every mail server the message touched, oldest first. A legitimate message usually shows a short, sensible chain; a surprise relay in an unexpected country is worth a second look.
- Identity headers show who the message says it's from. When the visible
Fromand the envelopeReturn-Pathdisagree — or the display name hides a different address — that's a classic phishing trick.
Want this checked automatically for every message? Publishing your own SPF, DKIM, and DMARC records is what lets other inboxes reject forgeries that impersonate your domain. Scan your domain free →
Keep hardening your email
Each record is one layer. Check the rest of yours — every tool is free, no account.
Email security scan
Run all 8 checks at once
SPF builder
Assemble a clean SPF record
SPF analyzer
Count your real DNS lookups
DMARC generator
Build a v=DMARC1 record
DMARC validator
Grade a record you have
DMARC report analyzer
Read a rua= XML report
DKIM validator
Check a DKIM key
Blocklist checker
Are you on a DNSBL?
BIMI check
Get your logo in inboxes
MTA-STS
Force TLS on inbound mail
TLS-RPT
Get TLS failure reports
DMARC visibility
Ingest your rua= reports
Continuous monitoring
Catch record drift on a schedule