Skip to content
← All tools

Email Header Analyzer

Trace an email's delivery path and check SPF, DKIM and DMARC. Headers are parsed in your browser, never uploaded.

Every email carries a record of how it travelled: which servers handled it, how long each one held it, and whether the sender was who they claimed to be. It is all in the headers, which your mail client hides by default and which are close to unreadable raw. Paste them above to get the delivery path, the delays, and the SPF, DKIM and DMARC results — parsed in your browser rather than posted to a server.

Where to find the headers

Gmail — open the message, the three-dot menu, Show original.
Outlook — open the message, File, Properties, and copy the Internet headers box.
Apple MailView, Message, All Headers.
ThunderbirdView, Message Source, or Ctrl+U.

Paste the whole thing, body included if it is easier. Parsing stops at the first blank line, which is exactly where the headers end.

Reading the delivery path

Each server that handles a message adds a Received header at the topof the list. The raw order is therefore backwards — newest first — which is the single most common source of confusion when reading headers by hand. They are reversed here, so hop 1 is where the message started and the last row is where it arrived.

The delay column is the gap between one server's timestamp and the next. Most hops are a second or two. A gap of minutes at one hop is usually greylisting, where a receiving server deliberately rejects a first attempt and accepts the retry, or a queue on a busy relay. Neither is a network fault, and both look identical to "the email was slow" from the outside.

Timestamps come from the servers themselves, and server clocks disagree. A hop that appears to take negative time is clock skew, not time travel; it is shown as zero here rather than as a negative number.

SPF, DKIM and DMARC in one sentence each

SPF asks whether the server that sent this message is allowed to send for that domain. It breaks legitimately when mail is forwarded, because the forwarding server is not on the original list.

DKIM is a cryptographic signature over the message. It survives forwarding, and fails if anything modified the content in transit — which some mailing lists do by appending footers.

DMARC ties the other two to the domain a reader actually sees in the From line, and tells receivers what to do when they disagree. It is the one that decides whether a message is trusted, which is why dmarc=fail matters more than either of the others failing alone.

These verdicts are the receivingserver's findings, recorded in the message. They are a report, not a live check — a header can say spf=pass for a domain whose policy has changed since.

What a Return-Path mismatch does and does not prove

If Return-Path is a different domain from From, the tool says so. That is deliberately phrased as something to check rather than a verdict, because the mismatch is entirely normal for mailing lists, newsletters and anything sent through a bulk provider — the bounce address belongs to the sending platform, not the brand.

It is also what unsophisticated spoofing looks like. The way to tell them apart is the authentication block: a legitimate bulk sender will show DMARC passing despite the mismatch, because the domain owner authorised that platform. A spoof usually will not.

Related tools

DNS lookupto read a domain's SPF and DMARC records directly, IP address and ISP lookup to identify a sending host, and the connection report when a support ticket needs the rest.

Privacy note

Headers are more sensitive than they look: they contain your address, the sender's, the subject line, and frequently internal hostnames and IP addresses from inside a company network. The established analysers post all of that to a server. This one parses it in your browser — there is no upload, no storage, and no request made while you type. You can confirm that in your browser's network tab.

Common questions

How do I see the full headers of an email?
In Gmail, open the message, use the three-dot menu and choose Show original. In Outlook, open the message then File, Properties, and copy the Internet headers box. Apple Mail has View, Message, All Headers; Thunderbird uses Ctrl+U for Message Source. Paste the whole thing — parsing stops at the first blank line, which is where headers end.
Why are the Received headers in reverse order?
Each server adds its Received line at the top rather than the bottom, so the raw list runs newest to oldest — the opposite of how the message travelled. This tool reverses them, so hop 1 is where the message started and the last row is where it arrived.
Why did my email take so long to arrive?
Look for a single hop with a delay of minutes rather than seconds. That is usually greylisting, where a receiving server deliberately rejects the first attempt and accepts a retry a few minutes later, or a queue on a busy relay. Neither is a network fault, and both are invisible from the outside.
What do SPF, DKIM and DMARC actually mean?
SPF asks whether the sending server is authorised for that domain, and breaks legitimately when mail is forwarded. DKIM is a signature over the message that survives forwarding but fails if the content was modified in transit. DMARC ties both to the domain shown in the From line and decides what receivers do when they disagree — which is why a DMARC failure matters more than either of the others alone.
Does a Return-Path different from From mean the email is fake?
Not on its own. It is completely normal for mailing lists, newsletters and anything sent through a bulk provider, where the bounce address belongs to the platform rather than the brand. It is also what basic spoofing looks like. The authentication results tell them apart: a legitimate bulk sender still passes DMARC despite the mismatch.
Are the headers I paste sent anywhere?
No. Everything is parsed in your browser as you type — no upload, no storage, and no request made at all. That matters more here than for most tools, because headers contain your address, the sender's, the subject line and often internal hostnames and IP addresses.
Can I trust the authentication results in the headers?
They are the receiving server's own findings, recorded at delivery time — a report rather than a live check. They are trustworthy if you trust the server that wrote them, which for your own mail provider you generally do. A header can still say spf=pass for a domain whose policy has changed since.
Can I find the sender's real IP address from headers?
Sometimes. The earliest Received hop may name the originating host, but major providers deliberately strip or replace that for privacy, so with mail from Gmail or Outlook you usually see only the provider's infrastructure. Any address you do find can be checked with an IP or ISP lookup.

Also Check These Tools

🌐What Is My IPInstantly see your public IPv4 and/or IPv6 address with ISP, city, and country details.📡What Is My ISPSee which Internet Service Provider (ISP) or organization is associated with your public IP and connection.🔷What Is My DNSLook up public DNS A and AAAA records using Cloudflare DNS over HTTPS, with honest labeling about resolvers.📶Ping & Latency TestMeasure HTTPS round-trip time from your browser to this site—a practical “ping” when ICMP is not available in the web sandbox.🛜What Is My Network TypeDetect whether you are on Wi-Fi, cellular, or ethernet, with effective speed class and estimated bandwidth from the Network Information API.🔐What Is My VPN / Am I Leaking?Compare your HTTP-visible public IP with WebRTC ICE reflexive addresses to spot possible IP leaks, plus plain-language DNS leak context.Internet Speed TestTest your download and upload speeds with a fast, accurate in-browser speed test.🖥️What Is My BrowserDetect your browser name, version, engine, and operating system in one click.🔍What Is My User AgentSee the full user agent string your browser sends to websites and servers.🍪What Is My Cookie / Tracking StatusSee whether first-party cookies and web storage work, what DNT/GPC report, and visible cookie surface—plus honest limits for HttpOnly and cross-site tracking.📐What Is My Screen ResolutionCheck your screen resolution, color depth, pixel ratio, and viewport size.🎮What Is My WebGL / GPUDetect your GPU renderer, vendor, WebGL version, and key graphics capabilities directly from your browser — no plugins required.📍What Is My LocationDiscover your approximate location based on your IP address including city and country.🕐What Is My TimezoneFind your current timezone, UTC offset, and local time with DST status.🎞️What Is My Refresh RateMeasure your monitor’s real refresh rate (Hz) live in the browser — see whether 60, 120, 144 or 240 Hz is actually active, with frame-time stability.🔌Open Port CheckerCheck which TCP ports are open, closed, or filtered on your public IP address — no software needed.🚦ISP Throttling TestCheck whether your ISP is slowing video: compares download speed to Netflix’s servers against generic servers and says whether it looks like shaping or congestion.👻Invisible Character DetectorFind and remove zero-width characters, unusual spaces and hidden Unicode in any text. Checked in your browser.🎬Video File InspectorRead a video file's codec, resolution, duration and bitrate without uploading it. The file never leaves your browser.🔐Password Breach CheckCheck whether a password appears in known data breaches. It is hashed in your browser and never sent anywhere.📋Connection ReportRun every network, browser and device check at once and copy one plain-text summary into a support ticket.🔀CGNAT TestFind out whether your ISP puts you behind carrier-grade NAT — the usual reason a forwarded port stays unreachable.