Email header analyzer

Paste the raw headers of a message (up to 200,000 characters) to see the route it took, where it waited, and what the receiving server concluded about SPF, DKIM and DMARC. The headers never leave your browser.

Parsed in your browser. The text you paste is not uploaded, stored or logged: this page makes no network request with it.

What the analyzer reads

Every mail server that handles a message adds a Received header on top of the existing ones, so the list reads from the bottom (the first server) to the top (your mailbox). The analyzer unfolds the headers, puts the hops in chronological order, converts each timestamp to UTC and shows how long the message spent between one hop and the next. A long gap points at the server that held it.

It then reads Authentication-Results, the header in which the receiving server records its SPF, DKIM, DMARC and ARC verdicts, together with the domains each verdict was about; the DKIM-Signature domains and selectors; and whether the Return-Path and DKIM domains line up with the visible From domain, which is what DMARC means by alignment. Message-ID, X-Spam headers and the presence of List-Unsubscribe are listed as well.

Private by construction

Headers contain addresses, internal host names and sometimes tokens. This page parses them with JavaScript in your browser: the text you paste is not sent to OrbitProbe or anywhere else, not stored and not logged. You can confirm that in the Network tab of your browser's developer tools, or use the page after disconnecting from the network.

How far to trust headers

Only the headers added by your own provider are trustworthy. Everything below the first hop that you trust was supplied by earlier servers, and a sender can insert forged Received lines to disguise the origin. Read Authentication-Results from the top-most header written by your receiving server, and treat older ones, including those carried in ARC sets, as claims by intermediaries.

Server clocks differ, so a delay of a few seconds, or a small negative one, means nothing. The analyzer shows negative delays as they are rather than hiding them.

How to use this tool

  1. Copy the raw headers. Open the message in your mail program and choose "Show original", "View source" or "All headers". Copy everything above the body.
  2. Paste and analyze. Paste the text into the box. It is parsed in your browser; nothing is uploaded.
  3. Read hops and verdicts. Follow the hops from first to last with their delays, then check the SPF, DKIM and DMARC verdicts and the domain alignment.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • Received lines of a saved message, oldest firstformail -c -x Received: < message.eml | tac
  • Authentication verdicts of a saved messageformail -c -x Authentication-Results: < message.eml
  • Without formailsed "/^$/q" message.eml | grep -iE "^(received|authentication-results|dkim-signature|return-path|from):"

FAQ

How do I get the full headers of an email?

In Gmail open the message menu and choose "Show original". In Outlook open the message properties or "View message source". In Apple Mail use View, Message, All Headers. Copy everything above the message body.

Is my email uploaded?

No. The parsing happens in your browser and the page makes no network request with your text. You only need the headers, not the body.

How do I read the Received lines?

From bottom to top. The lowest one is the first server that accepted the message, the top one is the last. The analyzer reverses them for you and numbers the hops.

What does spf=pass, dkim=pass, dmarc=fail mean?

SPF or DKIM passed for some domain, but not for a domain aligned with the visible From address. DMARC needs a pass that is aligned, so check which domains appear in smtp.mailfrom and header.d.

Can I find the sender's real location from the headers?

Not reliably. Webmail and large providers do not record the author's IP address, and headers below your provider's hop can be forged.