✉️ Email Header Analyzer
Paste the raw headers of an email to review its delivery path and authentication results for phishing and mail-delivery investigations. Everything is processed locally in your browser — the headers are never uploaded.
Input
Results
How It Works
The tool splits the pasted text into individual headers (handling folded lines), pulls out the sender, recipient, subject, and message identifiers, and parses every Received header to reconstruct the route the message took — displayed oldest hop first, even though mail servers write them newest first.
SPF, DKIM, and DMARC results are read from the Authentication-Results header added by the receiving mail server. They are reported, not recalculated — recomputing them from headers alone would be unreliable. Header analysis cannot, by itself, prove that an email is legitimate or malicious, and Received headers added below the first server you trust can be forged by the sender.
Examples & Common Use Cases
- Check whether a suspicious message passed SPF, DKIM, and DMARC at your mail provider.
- See which servers handled the message and when, to spot unexpected relays or long delays.
- Compare the From, Reply-To, and Return-Path domains for mismatches worth reviewing.