All tools

Email Header Analyzer

Trace a message's delivery path and read its SPF, DKIM and DMARC results — in your browser.

Everything here runs entirely in your browser. Nothing you type, paste, or upload is ever sent to a server, logged, or stored.

About the Email Header Analyzer

Takes the raw headers of a message and lays out its delivery path hop by hop, along with the SPF, DKIM and DMARC results the receiving mail servers recorded, so you can see where a message actually came from rather than what the From line says.

When you would use it

  • Working out whether a suspicious message is genuinely from who it claims.
  • Finding which hop introduced a delay when mail arrives late.
  • Checking that your own outbound mail is passing authentication.

What it does not tell you

The authentication results are READ OUT of the headers, not re-tested. Headers are just text, so a message that never passed through a real mail server can claim any result it likes and this tool will report it at face value. What makes the reading trustworthy is the identity of the server that stamped it — a result added by your own provider means something, one added by an unknown host means nothing. Everything is parsed in your browser.

Is this email a phishing attempt? A step-by-step walkthrough