Paste an email's raw headers to see where it really came from, whether it passed SPF, DKIM and DMARC, and whether replies would go somewhere else.
Headers are parsed and judged in your browser. Nothing you paste is uploaded or stored.
The name and address you see at the top of an email are just text the sender typed. Anyone can put your bank's name in the From field. What they cannot easily fake is the trail every message collects on its way to you: the servers it passed through, and the authentication checks your email provider ran when it arrived. That trail is in the headers, hidden by default in every email app.
This analyser reads those headers for you. It shows who the message claims to be from and where a reply would actually go, rebuilds the delivery path from the sending server to your inbox, and translates the SPF, DKIM and DMARC results into plain language. Then it flags the specific tricks used in impersonation and invoice fraud.
Business email compromise is one of the costliest forms of online fraud. A criminal sends a message that appears to come from a supplier, a solicitor or a company director, asking for an urgent payment or new bank details. Often the From address looks right and only the Reply-To is different, so every reply goes straight to the criminal. The header analyser surfaces that mismatch immediately.
Many phishing emails come from domains that have no email protection at all, so they pass no authentication. Others come from lookalike domains that pass authentication perfectly for the wrong domain. Reading which domain actually signed the message catches both.
When a message fails DMARC, the domain owner usually told receivers to quarantine or reject it. If it still reached your inbox, your provider chose to deliver it anyway, and it deserves more suspicion, not less.
Headers are also evidence. If you report fraud to your bank, your employer's IT team or a regulator, the raw headers show where the message came from in a way a screenshot cannot.
In Gmail on the web, open the message, select the three dot menu and choose Show original. In Outlook on the web, open the message, select the three dot menu, then View and View message source. In Outlook for Windows, open the message and choose File, then Properties. The full instructions for other apps are in the tool above.
Usually not in any useful way. Headers show the IP addresses of mail servers, which belong to email providers and hosting companies. Major providers such as Gmail do not include the sender's own IP address. At most you learn the network or rough region a server is in.
SPF fail means the sending server was not authorised to send for that domain. DKIM fail means the signature was missing or did not verify, so the message may have been altered or not signed by that domain. DMARC fail means the From address you see did not line up with a domain that passed either check, which is the clearest sign of spoofing.
Check whether DMARC passed, whether the DKIM signing domain matches the company you expect, and whether the Reply-To points to a different domain from the From address. A failed DMARC check or a Reply-To on an unrelated domain are strong signs of a forged message.
Gmail and several other large providers remove the original sender's IP address to protect user privacy. You will see Google's own servers in the path instead. That is normal and not a sign of anything suspicious.
Yes. Headers include your email address and the server names of your provider, but this analyser works entirely in your browser and nothing is sent to us. You can disconnect from the internet after the page loads and it still works.