Email Header Analyzer

Paste a message's raw headers to see where it came from, how long each hop took and whether it passed authentication.

Privacy: E-mail headers contain personal information: names and addresses of the sender and recipients, IP addresses and subject lines. Only paste headers you are entitled to share. They are processed in memory to produce this page and are not stored, logged or cached.

Result

Looks good

Checked

  • OK

    DMARC passed

    Your provider confirmed that the visible From domain (example.com) was authenticated by SPF or DKIM in an aligned way.

  • OK

    SPF passed

    The sending server is authorised by the SPF record of bounce@mail.example.com.

  • OK

    DKIM signature verified

    At least one DKIM signature was valid (signed by example.com).

  • Info

    Some hops do not show TLS encryption

    Hop(s) 1, 3 were recorded as plain SMTP. Servers do not always record TLS in the Received line, so this is not conclusive.

SPFpass
DKIMpass
DMARCpass

Results recorded by mx.example.net (top-most Authentication-Results header).

Message summary

From"Example Shop" <orders@example.com>
Toalex@example.net
Reply-Tosupport@example.com
Return-Path<bounce@mail.example.com>
SubjectYour order № 10423 has shipped
DateTue, 22 Sep 2026 16:14:04 +0000
Message-ID<20260922161404.4Wx1Yz2AbCz9sQ@mail.example.com>

Delivery path (3 hops, total 2 s)

  1. 1
    From
    app01.internal.example.com [10.0.4.17]
    By
    mail.example.com
    With
    ESMTP
    Time
    2026-09-22 16:14:05 UTC
    Raw Received headerfrom app01.internal.example.com (app01.internal.example.com [10.0.4.17]) by mail.example.com (Postfix) with ESMTP id 4Wx1Yz2AbCz9sQ for <alex@example.net>; Tue, 22 Sep 2026 16:14:05 +0000 (UTC)
  2. 2 +2 s
    From
    mail.example.com [192.0.2.25]
    By
    mx.example.net
    With
    ESMTPS TLS
    Time
    2026-09-22 16:14:07 UTC
    Raw Received headerfrom mail.example.com (mail.example.com. [192.0.2.25]) by mx.example.net with ESMTPS id m12si1234567pgd.123.2026.09.22.09.14.06 for <alex@example.net> (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 09:14:07 -0700 (PDT)
  3. 3 +0 s
    From
    By
    2002:a05:6a10:8e0e:b0:5d1:2f3a:1b2c
    With
    SMTP
    Time
    2026-09-22 16:14:07 UTC
    Raw Received headerby 2002:a05:6a10:8e0e:b0:5d1:2f3a:1b2c with SMTP id x14csp123456pxb; Tue, 22 Sep 2026 09:14:07 -0700 (PDT)

Authentication-Results headers

Top-most (your provider) · mx.example.net

MethodResultDetails
dkimpass header.i=@example.com header.s=s1 header.b=AbCdEf12
spfpass smtp.mailfrom=bounce@mail.example.com (example.net: domain of bounce@mail.example.com designates 192.0.2.25 as permitted sender)
dmarcpass header.from=example.com (p=REJECT sp=REJECT dis=NONE)

DKIM signatures

All 18 header fields
Delivered-Toalex@example.net
Receivedby 2002:a05:6a10:8e0e:b0:5d1:2f3a:1b2c with SMTP id x14csp123456pxb; Tue, 22 Sep 2026 09:14:07 -0700 (PDT)
X-Receivedby 2002:a17:90a:d58e:b0:2c9:81a3:4f10 with SMTP id l14mr1234567pju.5.1790000047123; Tue, 22 Sep 2026 09:14:07 -0700 (PDT)
ARC-Authentication-Resultsi=1; mx.example.net; dkim=pass header.i=@example.com header.s=s1 header.b=AbCdEf12; spf=pass (example.net: domain of bounce@mail.example.com designates 192.0.2.25 as permitted sender) smtp.mailfrom=bounce@mail.example.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=example.com
Return-Path<bounce@mail.example.com>
Receivedfrom mail.example.com (mail.example.com. [192.0.2.25]) by mx.example.net with ESMTPS id m12si1234567pgd.123.2026.09.22.09.14.06 for <alex@example.net> (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 09:14:07 -0700 (PDT)
Received-SPFpass (example.net: domain of bounce@mail.example.com designates 192.0.2.25 as permitted sender) client-ip=192.0.2.25;
Authentication-Resultsmx.example.net; dkim=pass header.i=@example.com header.s=s1 header.b=AbCdEf12; spf=pass (example.net: domain of bounce@mail.example.com designates 192.0.2.25 as permitted sender) smtp.mailfrom=bounce@mail.example.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=example.com
DKIM-Signaturev=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=s1; t=1790000045; h=from:to:subject:date:message-id; bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=; b=AbCdEf12...
Receivedfrom app01.internal.example.com (app01.internal.example.com [10.0.4.17]) by mail.example.com (Postfix) with ESMTP id 4Wx1Yz2AbCz9sQ for <alex@example.net>; Tue, 22 Sep 2026 16:14:05 +0000 (UTC)
From"Example Shop" <orders@example.com>
Reply-Tosupport@example.com
Toalex@example.net
Subject=?UTF-8?Q?Your_order_=E2=84=96_10423_has_shipped?=
DateTue, 22 Sep 2026 16:14:04 +0000
Message-ID<20260922161404.4Wx1Yz2AbCz9sQ@mail.example.com>
MIME-Version1.0
Content-Typetext/html; charset=UTF-8

These headers were processed in memory for this page only and have not been stored.

About this tool

Every server that handles an e-mail adds a Received: line to the top of its headers, and your mail provider adds an Authentication-Results: line with the SPF, DKIM and DMARC outcome. Read together, they show the path the message took.

To get the headers: in Gmail choose ⋮ → Show original; in Outlook on the web … → View → View message source; in Outlook desktop File → Properties → Internet headers; in Apple Mail View → Message → All Headers.

How to read the results

The timeline is shown from the first server to your inbox (the reverse of the order in the headers). Delays show how long the message waited between hops; small negative values usually mean a server clock is off.

The authentication summary uses the top-most Authentication-Results header, because that one was added by your own provider. Lower Received and Authentication-Results headers were written by earlier servers — including, possibly, the sender — and cannot be fully trusted.

Findings are worded cautiously on purpose: many signs of phishing (a different Reply-To, a failed SPF check) also occur in legitimate mail. Treat them as reasons to look closer, not as verdicts.

Limitations

  • The analyzer reads what the headers say; it does not re-verify DKIM signatures or re-run SPF, because that needs the message body and the DNS state at the time of delivery.
  • Servers write Received lines in slightly different formats. Unusual formats may be shown partly unparsed.
  • Anything below the first Received header added by your provider can be forged by the sender.

Frequently asked questions

Is it safe to paste my headers here?

The headers are sent over HTTPS, processed in memory to build the page and then discarded. They are not saved to a database, log file or cache. Still, only paste headers you are allowed to share, and consider removing addresses you do not need analysed.

How can I tell if an e-mail is phishing?

Check that DMARC passed for the domain in the From address, that the Reply-To goes to the same organisation, and that links point where they claim. A DMARC pass means the domain is genuine — but attackers also register look-alike domains, so read the domain carefully.

Why does SPF fail on a legitimate message?

Forwarding and mailing lists resend the message from their own servers, which are not in the original sender's SPF record. DKIM normally survives, so DMARC can still pass.

What does ARC mean in the headers?

ARC (Authenticated Received Chain, RFC 8617) lets intermediaries such as mailing lists record the authentication results they saw before modifying a message, so the final receiver can take them into account.

Are my headers stored?

No. They are processed in memory and discarded.

Which header shows the real sender?

The Received headers added by your provider and the DMARC result.

Can headers be faked?

Yes, except those added by your own mail provider.