Paste the raw headers of a suspicious email to see whether it passed SPF, DKIM, and DMARC, trace the servers it travelled through, find where it really came from, and surface the spoofing tricks phishers use. Everything is analyzed locally — the headers never leave your browser.
Parsing runs entirely in your browser. Header contents are never transmitted or stored.
SPF, DKIM, and DMARC are the three email-authentication checks. A DMARC pass means the message genuinely came from the domain it claims; a DMARC fail is a strong spoofing signal. The Received chain lists every mail server the message passed through, oldest at the bottom — the originating IP is usually in that bottom hop, and you can pivot it into our IP intelligence. A Reply-To or Return-Path pointing to a different domain than the From address is a classic business-email-compromise tell. Test your own instincts with the phishing quiz.
In Gmail, open the message, click the three-dot menu, and choose 'Show original'. In Outlook, open the message and use File → Properties, or 'View source'. Copy the full header block and paste it here.
Yes. All parsing runs locally in your browser. The header contents are never transmitted, logged, or stored, so you can safely analyze sensitive messages.
DMARC ties SPF and DKIM to the visible From domain. A fail means the message could not be authenticated as genuinely from that domain — a strong indicator of spoofing or phishing, especially combined with an SPF fail or a mismatched Reply-To.
Attackers can forge display names and some fields, but the Authentication-Results and Received headers are added by the receiving mail infrastructure and are much harder to fake. That is why this tool weights authentication results and routing over the visible From line.