Email Header Analyzer
Paste the raw headers of an email to see where it came from, how long each hop took, and whether SPF, DKIM and DMARC passed. It all happens in your browser.
How it works
An email's headers are the log of its journey. Each server that handles the message adds a Received line at the top, so the tool reads them from the bottom up to show the route in the order the message travelled, with the time spent at each hop. The receiving server also adds an Authentication-Results header recording whether SPF, DKIM and DMARC passed, and the tool reads those too.
It then compares the From, Reply-To and Return-Path domains and the DKIM signing domain, and lists anything that looks off. A mismatch isn't proof of anything wrong, since mailing services legitimately send on behalf of other domains, so read the findings as prompts to look closer.
| Result | Meaning |
|---|---|
pass | The check succeeded. |
fail | The check ran and the message did not meet it. |
softfail | SPF: the sender is probably not allowed, but the domain asked receivers not to reject outright. |
neutral / none | The domain makes no claim, or has no record. |
temperror / permerror | A temporary or permanent error while checking, often a DNS or record syntax problem. |
To look up the records behind a result, use the DNS Lookup Tool: query TXT on the domain for SPF, and on _dmarc.yourdomain.com for DMARC.
Frequently asked
Is it safe to paste my email headers here?
Yes. The headers are parsed in your browser and are never sent to Curious Assistant or any other server. They can contain IP addresses and email addresses, so avoid posting them publicly, but analysing them here keeps them on your device.
Where do I find the raw headers?
In Gmail, open the message, click the three dots and choose Show original. In Outlook, open the message, then File, Properties, and copy the Internet headers box. In Apple Mail, choose View, Message, All Headers. Copy everything from the first line down.
What do SPF, DKIM and DMARC mean?
SPF checks that the sending server is allowed to send for the domain. DKIM checks a cryptographic signature added by the sending domain. DMARC ties them together and says what to do if the From address doesn't line up with a passing SPF or DKIM result. A message can pass SPF and DKIM and still fail DMARC if the domains don't align.
Why does a message from a real company fail DMARC?
Usually because a mailing service sent it using its own domain for SPF and DKIM without being set up to sign as the company's domain. The company needs to configure the service to sign with its own domain. It is a setup mistake far more often than a forgery.
Can this tell me whether an email is a scam?
It gives clues, not a verdict. Failed authentication, a Reply-To pointing somewhere unrelated and a route that starts at an unexpected server are all worth noticing. A passing result doesn't make a message safe, because scammers can authenticate their own domains.