Email Header Analyzer

Paste an email's raw headers to see where it really came from, whether it passed SPF, DKIM and DMARC, and whether replies would go somewhere else.

Headers are parsed and judged in your browser. Nothing you paste is uploaded or stored.

The name and address you see at the top of an email are just text the sender typed. Anyone can put your bank's name in the From field. What they cannot easily fake is the trail every message collects on its way to you: the servers it passed through, and the authentication checks your email provider ran when it arrived. That trail is in the headers, hidden by default in every email app.

This analyser reads those headers for you. It shows who the message claims to be from and where a reply would actually go, rebuilds the delivery path from the sending server to your inbox, and translates the SPF, DKIM and DMARC results into plain language. Then it flags the specific tricks used in impersonation and invoice fraud.

How it works

  1. Open the suspicious email in a desktop browser and copy its raw headers using the instructions for your email app. Paste them into the box.
  2. The analyser unfolds wrapped header lines and separates each header, ignoring the message body if you pasted the whole thing.
  3. The From, Reply-To and Return-Path addresses are extracted and compared. A reply going to a different domain from the one shown is one of the most important signals.
  4. Each Received line is parsed and the list is reversed, so the path reads from the original sender to your inbox, with the delay at every hop.
  5. The Authentication-Results header added by your own email provider is read for the SPF, DKIM and DMARC outcomes, along with the DKIM signing domain.
  6. The findings are combined into a verdict with a one sentence reason and a list of specific warning signs.

Reading your results

  • Looks genuinely sent by the domain it claims: SPF, DKIM and DMARC all passed and no serious flags were found. The message really came from that domain, though a legitimate domain can still send a scam if its account was hacked.
  • We cannot confirm who sent this: the receiving server did not record authentication results, or they were mixed. Treat the message with normal caution.
  • Warning signs: something important does not line up, such as a Reply-To on a different domain or a failed check. Verify with the sender through another channel.
  • Likely did not come from who it claims: DMARC failed, or both SPF and DKIM failed. The visible From address is very probably forged.
  • SPF pass means the sending server is on the list of servers allowed to send for the envelope domain. It does not check the From address you see.
  • DKIM pass means a cryptographic signature proves the message was not changed and names a signing domain. Check that domain is the one you expect.
  • DMARC pass means the visible From domain matches a domain that passed SPF or DKIM. It is the check that ties authentication to what you actually see.
  • The delivery path is only trustworthy from the point it reached a server you trust. Lines added before that can be forged by the sender.

How this fits into the real world

Business email compromise is one of the costliest forms of online fraud. A criminal sends a message that appears to come from a supplier, a solicitor or a company director, asking for an urgent payment or new bank details. Often the From address looks right and only the Reply-To is different, so every reply goes straight to the criminal. The header analyser surfaces that mismatch immediately.

Many phishing emails come from domains that have no email protection at all, so they pass no authentication. Others come from lookalike domains that pass authentication perfectly for the wrong domain. Reading which domain actually signed the message catches both.

When a message fails DMARC, the domain owner usually told receivers to quarantine or reject it. If it still reached your inbox, your provider chose to deliver it anyway, and it deserves more suspicion, not less.

Headers are also evidence. If you report fraud to your bank, your employer's IT team or a regulator, the raw headers show where the message came from in a way a screenshot cannot.

Who this is for

  • Anyone who received an email asking for payment, new bank details, a login or a gift card purchase.
  • Bookkeepers, finance and office staff who handle supplier invoices.
  • IT and security staff triaging reported phishing.
  • Anyone who wants to learn how spoofing actually works.

What this tool cannot tell you

  • It reports the authentication results your email provider recorded. It does not re-run SPF, DKIM or DMARC itself.
  • A message from a hacked but legitimate account will pass every check. Authentication proves where a message came from, not that its request is honest.
  • Delivery path lines added before the message reached a trusted server can be forged, and some providers hide the sender's IP address for privacy.
  • Mobile email apps usually cannot show raw headers, so you may need a desktop browser.
  • IP addresses identify servers and networks, not individual people or home addresses.

Frequently asked questions

How do I find the email header in Gmail or Outlook?

In Gmail on the web, open the message, select the three dot menu and choose Show original. In Outlook on the web, open the message, select the three dot menu, then View and View message source. In Outlook for Windows, open the message and choose File, then Properties. The full instructions for other apps are in the tool above.

Can I find someone's location from an email header?

Usually not in any useful way. Headers show the IP addresses of mail servers, which belong to email providers and hosting companies. Major providers such as Gmail do not include the sender's own IP address. At most you learn the network or rough region a server is in.

What does SPF, DKIM or DMARC fail mean?

SPF fail means the sending server was not authorised to send for that domain. DKIM fail means the signature was missing or did not verify, so the message may have been altered or not signed by that domain. DMARC fail means the From address you see did not line up with a domain that passed either check, which is the clearest sign of spoofing.

How can I tell if an email is spoofed?

Check whether DMARC passed, whether the DKIM signing domain matches the company you expect, and whether the Reply-To points to a different domain from the From address. A failed DMARC check or a Reply-To on an unrelated domain are strong signs of a forged message.

Why does the sender's IP not show for Gmail messages?

Gmail and several other large providers remove the original sender's IP address to protect user privacy. You will see Google's own servers in the path instead. That is normal and not a sign of anything suspicious.

Is it safe to paste my email headers into this tool?

Yes. Headers include your email address and the server names of your provider, but this analyser works entirely in your browser and nothing is sent to us. You can disconnect from the internet after the page loads and it still works.

Related tools

Guides that go with this tool