Email Header Analyzer
Paste the full headers of an email to see the servers it really passed through, the address it came from, and whether SPF, DKIM and DMARC actually passed. The headers are the part a forger cannot fully control — which is why a convincing phishing message usually falls apart here.
Nothing is uploaded. The parsing runs entirely in your browser, so the contents of your email never leave this device.
All headers
Key takeaway: the From: line is typed by the sender and proves nothing at
all. What matters is whether the domain in From: matches the domain that actually authenticated
— the smtp.mailfrom in SPF and the d= in the DKIM signature. When those disagree
and DMARC fails, you are looking at a forgery.
Where to find the headers
Every mail client hides them, because almost nobody needs them. The full set is sometimes called the “original message”, “source” or “internet headers”.
| Client | How to get them |
|---|---|
| Gmail (web) | Open the message, click the three dots beside Reply, choose Show original, then copy everything in the panel. |
| Outlook (web) | Open the message, three dots, View → View message details. |
| Outlook (desktop) | Double-click to open the message in its own window, then File → Properties → Internet headers. |
| Apple Mail | View → Message → All Headers, or Command-Shift-H. |
| Thunderbird | View → Message Source, or Control-U. |
| Proton Mail | Three dots on the message → View headers. |
Forwarding the email to yourself does not work — forwarding creates a brand-new message with brand-new headers, and the original chain is lost. Always copy the source from the message itself.
What the three authentication results mean
These are the only parts of an email that are cryptographically or administratively checkable. Everything else — sender name, logo, wording, even the reply address — is free text.
SPF asks whether the server that delivered this message is on the list of servers the sending domain authorised. A pass means the message came from an approved machine. It checks the envelope sender, which is not necessarily the address you see in your mail client — which is precisely the loophole DMARC exists to close.
DKIM is a cryptographic signature over the message, made with a key published in the
sending domain’s DNS. A pass means the content genuinely came from that domain and was not altered in
transit. The domain that signed is the d= value, and it is worth reading: a message can carry a
valid DKIM signature from a domain that has nothing to do with the brand it claims to be.
DMARC ties the other two to the address you actually see. It passes only when SPF or DKIM
passed and the authenticated domain lines up with the From: domain. This is the check
that matters, and it is why a phishing email can show spf=pass and still be caught: the spammer
passed SPF for their own throwaway domain, not for the bank they are impersonating.
A pass is not a guarantee
All three checks verify the domain, not the intent. A phishing campaign that registers
paypa1-secure.com, configures SPF and DKIM properly and sends from its own servers will show
three green passes. That is why the domain-age check on the
WHOIS lookup pairs so well with this tool: authentic
infrastructure on a two-week-old domain is the signature of a scam, not of a bank.
Reading the Received chain
Each server that handles a message adds a Received: line at the top, so the list
reads newest-first in the raw source. This tool reverses that, numbering them in the order the message
actually travelled — hop 1 is where it entered the mail system, and the last hop is your own provider.
Two things are worth looking at. The first hop’s IP address is the closest thing to an origin you will get, and you can look it up to see which network it belongs to. And the gaps between timestamps show where a message sat in a queue — a multi-hour delay usually means greylisting or a backlog, not anything sinister.
Be careful about how much you read into the earliest hops. A sender’s own mail server writes those lines and a forger can invent as many as they like, so anything below the first server your provider controls is unverified. The hops added by your provider are the trustworthy part of the chain.
Some mail clients add the sender’s home IP address in the first
Received line, meaning the recipient can see roughly where you are. Webmail in a browser
usually does not; desktop clients sending over SMTP often do. If that matters to you, send through webmail
or over a VPN.
Affiliate links. We do not rank by commission — compare providers yourself.
What this cannot tell you
Who sent it. Headers identify machines and domains, never people. An origin IP belonging to a hosting company tells you which company to complain to, not who rented the server.
Where the sender is. The first IP is frequently a mail provider’s outbound server, not the sender’s computer — so its location is the data centre’s, not theirs.
Whether the content is safe. Authentication says the domain is real. It says nothing about links or attachments, and plenty of malicious mail is sent from properly configured domains, including compromised legitimate accounts.
Anything, if the headers are partial. Copying only the visible From and Subject lines leaves nothing to check. The chain and the authentication results are what carry the information.
Frequently asked questions
SPF says pass but the email is obviously fake. How?
Because SPF checks the envelope sender, which the recipient never sees. A scammer can pass SPF for their
own domain while the From: line displays a bank. Look at DMARC instead — that is the check that
requires the two to match, and it is the one that fails on this kind of forgery.
Can headers be faked?
The ones added before the message reached a real mail system, yes — including invented Received
lines designed to mislead. What cannot be faked is what your own provider recorded on arrival, or a DKIM
signature, which is cryptographic and fails if anything was altered.
Does the origin IP identify the sender’s computer?
Rarely. Webmail sends from the provider’s servers, so you get Google or Microsoft rather than a person. A desktop client on a home connection sometimes does expose the sender’s address in the earliest hop.
What does a big time gap between hops mean?
Almost always greylisting — a deliberate short delay many servers apply to unknown senders — or a queue on a busy server. It is a normal part of mail delivery and not a sign of tampering.
Is it safe to paste my headers here?
Yes. The parsing is JavaScript running in your browser; nothing is transmitted to us or anyone else. You can verify that by opening this page with your network disconnected — it still works.
Related reading
- How DNS works
- IP spoofing explained
- Is this a scam?
- What SSL/TLS protects
- What your IP reveals
- What someone can do with your IP
- How ransomware arrives
- Remove yourself from data brokers