thoughtasylumTOOLBOX Preview

Tools › Email

Email Header Analyser

Paste an email's headers to see who really sent it, the servers it passed through and how long each took, and whether it passed SPF, DKIM and DMARC, with anything that looks like spoofing or phishing pointed out.

About this tool What it's for, how to use it and an example

What it's for

Read the part of an email you don’t normally see. The headers record where a message really came from, every server it passed through and when, and whether the receiving server could prove the sender was genuine (the SPF, DKIM and DMARC checks). This lays that out and points out the signs of a spoofed or phishing message.

For example, when an email that says it’s from your bank asks you to “confirm your details”, paste its headers here to see whether it failed DMARC or sends replies somewhere else.

How to use it

Paste the headers, or the whole message, and it’s read as you type. To get them:

  • Gmail: open the message, choose the ⋮ menu, then Show original.
  • Outlook: open the message, then File › Properties (desktop) or ⋯ › View › View message source (web), and copy the internet headers.
  • Apple Mail: View › Message › All Headers or Raw Source.

You get a list of anything worth a look, a summary (sender, reply address, subject, authentication results, the DKIM signer, total delivery time), the route from the first server to the last with the delay at each step (a delay over 10 minutes is in red), and every header decoded.

Example

Paste this (made-up headers):

Received: from mail.shop.example (mail.shop.example [192.0.2.10])
	by mx.example.org with ESMTPS id a1; Mon, 5 Oct 2026 09:21:40 +0000
Received: from app1.shop.example (app1.shop.example [192.0.2.20])
	by mail.shop.example with ESMTP id b2; Mon, 5 Oct 2026 09:14:05 +0000
Authentication-Results: mx.example.org; spf=pass smtp.mailfrom=shop.example; dkim=pass header.d=shop.example; dmarc=pass header.from=shop.example
From: Shop <orders@shop.example>
Reply-To: refunds@shop-help.example
Subject: Your refund is ready
Date: Mon, 5 Oct 2026 09:14:02 +0000

The message says 7 headers, 2 hops and 1 thing to look at: replies go to refunds@shop-help.example, a different domain from the sender’s. Authentication shows SPF, DKIM and DMARC all passing, and the route shows the second hop took 7 min 35 s.

Good to know

It reads what the servers wrote; it doesn’t check anything over the internet. Only the top Authentication-Results header is used, as it’s the one your own mail provider added: lower ones could have been written by anyone. Every Received line below your provider’s own can be forged too, so the route before that point is only a claim.

Domains are compared by their last two parts (three for addresses such as .co.uk), so a few unusual domains may be flagged or missed wrongly. Headers hold names and email addresses, so this tool doesn’t offer a link to its input.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close