Email Header Analyzer

Works fully offline Email

Paste the raw headers from any email to see where it really came from, how long each server held it, whether it passed SPF, DKIM, and DMARC, and anything suspicious.

In Gmail, open the message menu and choose Show original. In Outlook, open the message and choose File → Properties (or View → View message details). Paste everything, or just the header part.

Overview

Every email carries a block of headers most mail apps hide. Each server that handles the message adds a Received line, so read from the bottom up they trace its route from the sender to your inbox with a timestamp at every step. The receiving server also records whether the message passed SPF, DKIM, and DMARC, the checks that prove a message was sent by who it claims.

This analyzer turns that block into something readable. It orders the delivery path oldest first and calculates the delay between hops, which pinpoints where a slow email got stuck. It shows each authentication result with the domain it applied to, decodes encoded subject lines and sender names, and lists every header in a table.

It also flags the patterns that deserve a second look. These include a Reply-To address on a different domain from the sender, failing DMARC or SPF, a missing DKIM signature, and a bounce address that doesn't match the sender when DMARC hasn't passed. A clean result doesn't guarantee a message is safe, but a failing DMARC on a message claiming to be from your bank is a strong sign it isn't.

Examples & Sample Data

A phishing attempt

Input
Authentication-Results: mx.example.org; spf=softfail smtp.mailfrom=paypa1.test; dkim=none; dmarc=fail (p=REJECT) header.from=paypal.com
From: "PayPal" <[email protected]>
Reply-To: [email protected]
Output
Replies go to paypa1-help.test, a different domain from the sender (paypal.com).
DMARC fail: the message didn't prove it came from paypal.com.
SPF softfail: the sending server isn't authorized by paypa1.test.
The message has no DKIM signature.

Finding a delivery delay

Input
Three Received headers from an online store's order confirmation
Output
Hop 2: smtp.sendgrid.net → mx.google.com, delay 48s
Hop 3: delivered to the mailbox, delay 1s
3 hops, 49s from first to last

How It Works

  1. Open the email and view its original source or message details. In Gmail, choose Show original from the message menu.
  2. Copy the headers, or the whole message, and paste them into the box.
  3. Read the warnings first, then the SPF, DKIM, and DMARC results.
  4. Check the delivery path to see each server, when it received the message, and how long each hop took.

Common Use Cases

Checking a suspicious email

Confirm whether a message claiming to be from a bank or delivery company actually passed authentication for that domain.

Debugging a delayed email

Find which server held a message for minutes or hours by comparing the timestamps between hops.

Verifying your own email setup

Send yourself a test message and confirm your domain's SPF, DKIM, and DMARC pass at a major mailbox provider.

Tips & Best Practices

  • Only trust the Received lines added by your own provider (the ones nearest the top). Lines lower down can be forged by a sender.
  • Mail sent through services like SendGrid or Mailchimp often has a bounce address on the service's domain. That's normal as long as DMARC passes.
  • If your own messages fail DMARC, check your records with the SPF, DKIM, and DMARC checkers.

Frequently Asked Questions

No. The headers are parsed entirely in your browser. That matters because headers include your email address, IP addresses, and internal server names.

In Gmail, open the message, click the three-dot menu, and choose Show original. In Outlook on the web, open the message's menu and choose View, then View message details. In Apple Mail, choose View, then Message, then All Headers.

SPF checks the sending server was allowed to send for the envelope domain. DKIM checks a cryptographic signature from the signing domain. DMARC passes when SPF or DKIM passes for the domain shown in the From address, which is the one you actually see.

Each server stamps the time from its own clock. If one server's clock is a few seconds off, a later hop can appear earlier. The analyzer labels this as clock skew rather than a real delay.

Related Tools

Explore more high-performance utilities.