Реклама

Paste raw email headers to trace the Received hops with delays and read SPF, DKIM and DMARC results — all in your browser. Free.

Paste the full raw headers of an email (in most clients: "Show original" or "View source"). Everything is parsed locally — no header ever leaves your browser.

Summary

From
To
Subject
Date
Return-Path
Message-ID

Authentication

SPF
DKIM
DMARC

Domain alignment

Delivery path (Received hops)

Read bottom-up: the last hop is where the message originated. Delays are the time added at each relay.

All headers


		
Реклама

За Email Header Analyzer

The Email Header Analyzer turns the wall of raw text at the top of an email into something readable. Paste the full headers and you get the sender, recipient, subject, date, Return-Path and Message-ID extracted first, followed by the authentication verdict and the complete delivery path.

Every Received header is parsed into a hop showing which host handed the message to which, when, and how much delay that relay added — read from the bottom up, the last hop is where the message originated. The SPF, DKIM and DMARC results are pulled from Authentication-Results (falling back to Received-SPF), and From is compared against Return-Path to flag domain misalignment, the classic spoofing tell.

The entire analysis runs in your browser. There is no upload, no server call and no logging: the headers you paste — which routinely contain internal hostnames, IP addresses and recipient addresses — never leave your machine. A sample header set is included if you just want to see how the output reads.

Как да използвате Email Header Analyzer

  1. Open the suspect message and copy its raw headers — “Show original” in Gmail, “View source” or “Properties” in most other clients.
  2. Paste the full block into the text area, or click “Load a sample” to try the tool first.
  3. Click “Analyze headers” and read the summary: From, To, Subject, Date, Return-Path and Message-ID.
  4. Check the SPF, DKIM and DMARC cards and the domain-alignment line beneath them.
  5. Walk the Received hops from the bottom up to see the true origin and which relay added the delay.

Често задавани въпроси

No. The parser is 100% client-side JavaScript: your headers are read, analysed and displayed inside your own browser and are never sent to our server, stored or logged. Close the tab and nothing remains.

In Gmail open the message menu and choose “Show original”. In Outlook open the message, then File, Properties, and copy the internet headers. In Apple Mail use View, Message, All Headers. Most webmail clients call it “view source”.

It gives you the strongest available signals: SPF, DKIM and DMARC results, and whether the visible From domain matches the Return-Path used for delivery. A message that fails authentication or shows mismatched domains deserves suspicion — but headers can be forged, so treat the verdict as evidence, not proof.

Each relay prepends its own line, so the list is in reverse chronological order. The bottom entry is the first server that handled the message — the closest thing to its real origin — and the delay column shows where the message sat waiting.

Yes, entirely free, with no account and no credits. Because nothing is sent to a server, there is no rate limit either — analyse as many messages as you like.

Сподели

Популярни търсения
email header analyzer analyze email headers email header trace read email headers online trace email received hops spf dkim dmarc header check message header analyzer email source viewer
Нуждаете се от помощ?
Открихте проблем с този инструмент? Кажете ни.
Докладване на проблем

Добавете този безплатен инструмент към собствения си уебсайт — копирайте и поставете кода по-долу.