Search tools

Search for a command to run...

Email Header Analyzer

Paste raw email headers to trace the route, see delays between servers, and check SPF, DKIM and DMARC results — useful for spotting spoofed or phishing emails.

How to use

  1. 1Copy the full headers: Gmail → ⋮ → Show original; Outlook → File → Properties → Internet headers.
  2. 2Paste them here to see authentication results and each hop.

How it's calculated

Received headers are read bottom-up (the first server is at the bottom). SPF, DKIM and DMARC results come from the receiving server's Authentication-Results header.

Frequently asked questions

What do SPF, DKIM and DMARC mean?

SPF checks the sending server is allowed for the domain, DKIM verifies a cryptographic signature, and DMARC ties them to the visible From address. A spoofed email usually fails DMARC.

Why does Reply-To differ from From?

Legitimate newsletters sometimes do this, but it's a classic phishing trick — replies go to the attacker.

Are my headers sent anywhere?

No — they're analyzed entirely in your browser.