Email Header Analyzer
Paste raw email headers to trace the route, see delays between servers, and check SPF, DKIM and DMARC results — useful for spotting spoofed or phishing emails.
How to use
- 1Copy the full headers: Gmail → ⋮ → Show original; Outlook → File → Properties → Internet headers.
- 2Paste them here to see authentication results and each hop.
How it's calculated
Received headers are read bottom-up (the first server is at the bottom). SPF, DKIM and DMARC results come from the receiving server's Authentication-Results header.
Frequently asked questions
What do SPF, DKIM and DMARC mean?
SPF checks the sending server is allowed for the domain, DKIM verifies a cryptographic signature, and DMARC ties them to the visible From address. A spoofed email usually fails DMARC.
Why does Reply-To differ from From?
Legitimate newsletters sometimes do this, but it's a classic phishing trick — replies go to the attacker.
Are my headers sent anywhere?
No — they're analyzed entirely in your browser.