Email Header Analyzer
Analyze Email Headers
Tool features
4 checks
Header Parsing
Comprehensive parsing of all email headers including From, To, Subject, Date, and more
Authentication Analysis
SPF, DKIM, and DMARC authentication results analysis
Routing Information
Detailed email routing path analysis through Received headers
Security Assessment
Security score calculation and authentication status verification
What are email headers & how they work
Every email carries a block of headers that mail clients hide by default. Each server that handles the message adds a Received line, and the receiving server records its SPF, DKIM and DMARC verdicts in Authentication-Results.
Reading those headers tells you where a message really came from, which servers it passed through and how long each hop took, and whether it authenticated as the domain in the From address. That is how you trace delivery delays, confirm a phishing email is spoofed, or find out why your own mail lands in spam.
Received
One line per hop; read from the bottom up to follow the path from sender to inbox.
Authentication-Results
The receiver’s SPF, DKIM and DMARC verdicts for the message.
ARC
Authenticated Received Chain: preserves auth results across forwarders and mailing lists.
How to use this tool
1
Copy the full headers
In Gmail use Show original; in Outlook open message Properties (desktop) or View message source; in Apple Mail use View > Message > All Headers.
2
Paste and analyze
Paste the complete header block, from the first Received line down, and run the analysis.
3
Check authentication
Review SPF, DKIM and DMARC results and whether each aligns with the From domain.
4
Follow the route
Trace the Received hops to see the originating server and where delays were added.
Related tools
5 tools
Email Spam Checker
Audit an email message before you send it — unsubscribe headers, HTML weight, hidden text, misleading links and subject-line problems
Email Health Checker
Comprehensive email deliverability check including SPF, DKIM, DMARC, and MX records
SPF Lookup
Check Sender Policy Framework (SPF) records for email authentication and mail server authorization
DKIM Lookup
Find DomainKeys Identified Mail (DKIM) records for email message signing and verification
DMARC Lookup
Check DMARC policy records for email authentication, reporting, and policy enforcement
Frequently asked questions
5 Q&A
Look at Authentication-Results. A message that fails DMARC, or passes SPF/DKIM only for a domain unrelated to the From address, did not come from that domain’s authorised senders. The earliest Received hop shows the real sending server.
The bottom one. Each server adds its line on top, so read from the bottom up. Lines added before the message reached your provider can be forged, so trust the hops added by your own mail provider most.
Compare the timestamps between consecutive Received hops. A large gap shows which server held the message, often because of greylisting, a queue backlog or a retry after a temporary failure.
Headers contain addresses, server names and IPs but not the message body. They are analysed in memory and not stored or logged. Remove anything you consider sensitive before pasting.