Email Header Analyzer
Paste an email’s raw headers to check SPF, DKIM and DMARC, trace every relay hop with its delay, catch phishing signals, and get a clear security score. Everything runs in your browser — nothing you paste is ever uploaded.
Paste email headers
SPF, DKIM & DMARC explained
The three checks that decide whether an email is really from who it claims.
A DNS record listing which servers may send mail for a domain. The receiver checks the connecting server’s IP against it. A pass means the server was authorized; fail/softfail means it was not.
A cryptographic signature added by the sending domain. The receiver verifies it with a public key in DNS. A pass proves the message wasn’t altered and really came from that domain.
Ties SPF and DKIM to the visible From domain (alignment) and tells receivers what to do on failure (none / quarantine / reject). A pass means the message is aligned and trusted.
Where to find the raw headers
Every mail client can show the raw source — here’s the path for the common ones.
| Gmail | Open the message → ⋮ menu → “Show original”. Copy everything. |
| Outlook (desktop) | Open the message → File → Properties → “Internet headers”. |
| Outlook.com / M365 | ⋯ menu → View → “View message source”. |
| Apple Mail | View → Message → “All Headers” (or Raw Source). |
More free IT tools
Fast, private, browser-only utilities from Anavem — no sign-up, no tracking.