Free tool
Paste raw message headers to analyze them. The analyzer reads the Authentication-Results line for SPF, DKIM and DMARC, rebuilds the route from every Received header with the delay at each hop, and shows the real sender behind the display name. Free, instant, and nothing you paste is stored.
In Gmail: Open email → Three dots menu → Show original → Copy headers
A full header block has thirty or more lines. These are the ones that answer the questions people bring to a header analyzer: who really sent this, did it authenticate, and where did the delay happen.
| Header | What it tells you |
|---|---|
| Received | One line per server hop, newest at the top. The chain is the route, and the timestamp gap between lines is the delay at that hop |
| Return-Path | The envelope sender that bounces go to. SPF is checked against this domain, not the From address |
| From and Reply-To | The visible sender and where replies go. A Reply-To on a different domain is a common phishing tell |
| Authentication-Results | The receiving server's verdict on SPF, DKIM and DMARC, with the domain each check used |
| Received-SPF | The SPF result and the IP it evaluated, written by the first receiving server |
| DKIM-Signature | The signing domain (d=), selector (s=), signed headers (h=) and the signature itself |
| ARC-Seal and ARC-Authentication-Results | Authentication results carried across forwarders and mailing lists so DMARC can still pass |
| Message-ID | A unique ID set by the sending system. Use it to find the message in provider logs |
| X-Mailer, X-Originating-IP and other X- headers | Non-standard headers added by clients and filters. Useful hints, never proof |
The analyzer reads all of these and turns the Received chain into a timeline. A message that passed SPF and DKIM but failed DMARC almost always has an alignment problem, which the DMARC checker confirms on the domain; a missing DKIM result points to the DKIM checker.
Every client hides the raw headers somewhere different. Copy the whole block, including the blank line at the end, and paste it into the analyzer above.
| Client | Where the headers are |
|---|---|
| Gmail (web) | Open the message, click the three-dot menu, choose Show original, then Copy to clipboard |
| Outlook (web) | Open the message, click the three-dot menu, choose View, then View message source |
| Outlook (desktop) | Open the message in its own window, then File, Properties. The headers are in the Internet headers box |
| Apple Mail | Open the message, then View, Message, All Headers. Raw Source shows the full message |
| Yahoo Mail | Open the message, click More, then View raw message |
| iPhone and Android mail apps | Not exposed in the apps. Open the same message in webmail or a desktop client |
If the result shows an authentication failure on your own domain, the fix is in DNS, not in the message: the SPF, DKIM and DMARC guide explains which record to repair, and the 550 5.7.1 guide decodes the bounce that usually arrives with it.
Get a comprehensive deliverability score for your domain.
Comprehensive domain analysis for all email records.
Validate your SPF records and ensure proper email authentication.
Verify DKIM signatures and public key configuration.
Test your emails against spam filters and improve deliverability.
Calculate optimal mailbox counts for your email infrastructure.
Email headers contain crucial information about an email's journey from sender to recipient, including authentication results, routing paths, and security indicators that help identify legitimate emails and detect potential threats.
Authentication results
SPF, DKIM, and DMARC verification status from receiving servers.
Routing information
Complete path showing each server the email passed through.
Security indicators
TLS encryption status and potential security warnings.
Detect spoofing
Identify authentication failures that indicate potential email spoofing.
Troubleshoot delivery
Find delays or issues in email routing and delivery paths.
Verify authenticity
Confirm legitimate senders through proper authentication.
FAQ
Email headers contain technical details about an email's journey, including sender and recipient information, timestamps, authentication results (SPF, DKIM, DMARC), and the path taken through various mail servers.
The process varies by email client. In Gmail, open the email, click the three dots, and select 'Show original'. In Outlook, open the email, go to File > Properties. In Apple Mail, press Command+Shift+H.
Analyzing headers helps troubleshoot delivery delays, verify if an email is legitimate or spoofed, identify the source of spam, and check if your own emails are passing authentication checks.
Yes, we process the headers locally or securely on our servers to provide the analysis. We do not store the content of your email headers after the analysis is complete.
The sending server was authorized for the envelope domain, but the DKIM signature did not verify. The usual causes are a message modified in transit (a mailing list or security gateway rewriting the body), a rotated key whose DNS record was removed, or a selector that never published. If DMARC still passes, SPF alignment carried it; if not, fix DKIM first.
Some can. A sender controls every header they write, including From, Reply-To, Date and any Received lines added before the message is handed off. What cannot be faked are the headers your own provider adds after that point: its Received line, Received-SPF and Authentication-Results. Read from the top down and trust only the hops you recognise.
InboxKit provides everything you need for guaranteed deliverability and security monitoring