Email Header Analyzer

Paste a message's full headers to unfold them, list the Received hops and read its SPF, DKIM and DMARC claims.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Analyze email headers controls

Showing an example. Edit to see your own.

Paste the full source of the message, not the rendered version. In most mail apps this is Show original or Show source. Folded lines, Received and Authentication-Results are read, and nothing is sent anywhere.

Processed in your browser. Your inputs stay on this device.

How to use Email Header Analyzer

  1. Open the message in your mail app and choose the option that shows the original or raw source rather than the reading view.
  2. Copy the header block from the first line to the blank line before the body, then paste it into the box.
  3. The hop table updates as you paste the header block.
  4. Read the hops from the newest line at the top, then read the findings, remembering that every SPF, DKIM and DMARC line is a claim written by whichever server added it.

Example: Email Header Analyzer

Read the headers of a newsletter to see which server handed it over and what the receiving server claimed about SPF, DKIM and DMARC.

You add
The example already in the box: a Return-Path, one Received header folded over three lines, an Authentication-Results line reading spf=pass; dkim=pass; dmarc=pass, then From, To, Subject, Date and Message-ID.
You get
Read 8 headers, 1 Received hop and 3 authentication claims, with 0 problems. The hop table holds one row: from mail.example.com, by mta.receiver.example, dated Mon, 29 Sep 2026 09:15:00 +0600. The findings carry one line each for the SPF, DKIM and DMARC pass claims.

Options

Email headers
The box takes one header block. A line that begins with a space or a tab is read as a continuation of the line above it, which is how a long Received or DKIM-Signature value is written.

Supported inputs and limits

One header block up to 200,000 characters and 2,000 header lines, with the first 100 Received lines described. The page reads text: it does not look up a DNS record, open a mailbox, or test a DKIM signature, so each SPF, DKIM, DMARC, ARC or BIMI result is repeated as a claim made in the message. A hop that does not line up with the line above it is reported as an observation about the text, because a relay that rewrites its own line produces the same reading, and that is not proof of forgery. The simplified header view in many mail apps leaves lines out, so the full source is what belongs in the box.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

What a header block can and cannot tell you

A header block is a record of what servers wrote as a message travelled, one line at a time from the bottom up. It shows the path, the addresses the sender asked to use, and the authentication results the last server recorded. What it cannot do is confirm any of that, because every line is text a machine added and no line is signed as a whole. Reading a message carefully means comparing the visible From address with Return-Path and Reply-To, reading the hop chain for gaps, and then checking the authentication claim against the domain's own published policy when the answer matters. For a message that asks for money, a password or a payment detail, treat a clean reading as a reason to keep checking rather than as a clearance.

RFC 5322: Internet Message Format, header fields and folding

RFC 8601: Message Header Field for Indicating Message Authentication Status

RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email

Questions about Email Header Analyzer

Where do I find the full headers?

Every mainstream mail app has a command that shows the source, usually named Show original, Show source, View source or View message details. In a desktop client it often sits under a More menu on the open message; in webmail it usually sits behind a small arrow beside the reply button. What you need is the block of field names and values above the message body.

Does a pass here mean the sender is genuine?

No. The page copies the result text out of the message. A pass written into a header says the server that added that line accepted the message, and a forged header can carry any words at all. Confirming a result properly means looking up the domain's published records and checking a signature against the message body, which happens on the receiving server.

Why does the hop list start at the top?

Each mail server adds its own Received line at the top of the block, so the newest line is the server that delivered the message to its destination and the last line is the machine the sender's client first reached. Reading down the table follows the message from delivery back towards its origin.

What does a hop mismatch mean?

It means one line names a server the line above it did not receive from. That can happen because a relay rewrote the line to hide an internal host name, because a line was removed, or because a script assembled the message. Treat it as a prompt to look more closely rather than as a verdict.

Are my headers sent anywhere?

No. Everything is read in this browser, and nothing is uploaded, logged or stored. The box keeps its text until you clear it or close the page, so clear it when you have finished if the message holds an address or an identifier you would rather not leave on screen.

Project manager: Tony Hines · Content updated 29 September 2026 · Report a problem