How to use Email Header Analyzer
- Open the message in your mail app and choose the option that shows the original or raw source rather than the reading view.
- Copy the header block from the first line to the blank line before the body, then paste it into the box.
- The hop table updates as you paste the header block.
- Read the hops from the newest line at the top, then read the findings, remembering that every SPF, DKIM and DMARC line is a claim written by whichever server added it.
Example: Email Header Analyzer
Read the headers of a newsletter to see which server handed it over and what the receiving server claimed about SPF, DKIM and DMARC.
Options
- Email headers
- The box takes one header block. A line that begins with a space or a tab is read as a continuation of the line above it, which is how a long Received or DKIM-Signature value is written.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
What a header block can and cannot tell you
A header block is a record of what servers wrote as a message travelled, one line at a time from the bottom up. It shows the path, the addresses the sender asked to use, and the authentication results the last server recorded. What it cannot do is confirm any of that, because every line is text a machine added and no line is signed as a whole. Reading a message carefully means comparing the visible From address with Return-Path and Reply-To, reading the hop chain for gaps, and then checking the authentication claim against the domain's own published policy when the answer matters. For a message that asks for money, a password or a payment detail, treat a clean reading as a reason to keep checking rather than as a clearance.
RFC 5322: Internet Message Format, header fields and folding
RFC 8601: Message Header Field for Indicating Message Authentication Status
RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email
Questions about Email Header Analyzer
Where do I find the full headers?
Every mainstream mail app has a command that shows the source, usually named Show original, Show source, View source or View message details. In a desktop client it often sits under a More menu on the open message; in webmail it usually sits behind a small arrow beside the reply button. What you need is the block of field names and values above the message body.
Does a pass here mean the sender is genuine?
No. The page copies the result text out of the message. A pass written into a header says the server that added that line accepted the message, and a forged header can carry any words at all. Confirming a result properly means looking up the domain's published records and checking a signature against the message body, which happens on the receiving server.
Why does the hop list start at the top?
Each mail server adds its own Received line at the top of the block, so the newest line is the server that delivered the message to its destination and the last line is the machine the sender's client first reached. Reading down the table follows the message from delivery back towards its origin.
What does a hop mismatch mean?
It means one line names a server the line above it did not receive from. That can happen because a relay rewrote the line to hide an internal host name, because a line was removed, or because a script assembled the message. Treat it as a prompt to look more closely rather than as a verdict.
Are my headers sent anywhere?
No. Everything is read in this browser, and nothing is uploaded, logged or stored. The box keeps its text until you clear it or close the page, so clear it when you have finished if the message holds an address or an identifier you would rather not leave on screen.