Email Header Analyser
Paste the raw headers of a message to see its delivery path, per-hop delays and authentication results. Parsed in your browser and never uploaded.
Headers are parsed on this page only. Nothing you paste is sent to our servers.
What an email header tells you
Every email carries a hidden record of its journey. Each mail server that handles the message adds a Received line at the top, so reading the headers from the bottom up shows where the message started, every server it passed through, and how long each hop took. The From address you see in your mail client is just text the sender typed. The headers show where it really came from.
The analyser also pulls out the three authentication results that matter. SPF checks whether the sending server was allowed to send for that domain. DKIM checks whether the message was signed by the domain and not altered in transit. DMARC combines the two and tells the receiving server what to do when they fail.
How to read the results
A message from a legitimate business will normally show SPF and DKIM passing, and DMARC passing with an alignment match. A message that claims to be from your bank, your supplier or your own company but shows SPF fail, DKIM none or DMARC fail was almost certainly not sent by them. That is the signature of spoofing and business email compromise.
Long delays between hops usually point at a greylisting or spam filter, not a fault. A Received line from an unexpected country or a residential ISP, on a message that should have come from a corporate mail system, is worth a closer look.
Where to find the raw headers
In Outlook on the web, open the message, choose the three-dot menu, then View, then View message source. In the Outlook desktop app, open the message and go to File, Properties, Internet headers. In Gmail, open the message menu and choose Show original. Copy everything and paste it into the box above.
Email Header Analyser: common questions
Is it safe to paste email headers into this tool?
Yes. The headers are parsed by JavaScript running in your browser and are never sent to our servers or anyone else. You can confirm this by loading the page and disconnecting from the internet before pasting.
What does SPF fail mean?
The server that sent the message is not listed in the sending domainās SPF record, so the domain owner never authorised it. On a message claiming to be from a business you know, that usually means the sender address was forged.
What is the difference between DKIM and DMARC?
DKIM is a cryptographic signature that proves the message was sent by the domain and not changed on the way. DMARC is a policy published by the domain owner that tells receiving servers what to do when SPF or DKIM fail, and asks for reports back. You need SPF and DKIM in place before DMARC does anything useful.
Can headers tell me exactly who sent an email?
They tell you which servers handled it and whether the sending domain authorised it. They will not identify a person. Attackers often send through legitimate but compromised accounts, so a message can pass every check and still be malicious. Treat authentication as one signal among several.
More free tools
Getting suspicious emails?
Headers that fail SPF, DKIM or DMARC on mail that claims to be from your own domain are a classic spoofing sign. We configure email authentication, Defender for Office 365 and staff phishing training as part of our cyber security service.
