What the analyzer reads
Every mail server that handles a message adds a Received header on top of the existing ones, so the list reads from the bottom (the first server) to the top (your mailbox). The analyzer unfolds the headers, puts the hops in chronological order, converts each timestamp to UTC and shows how long the message spent between one hop and the next. A long gap points at the server that held it.
It then reads Authentication-Results, the header in which the receiving server records its SPF, DKIM, DMARC and ARC verdicts, together with the domains each verdict was about; the DKIM-Signature domains and selectors; and whether the Return-Path and DKIM domains line up with the visible From domain, which is what DMARC means by alignment. Message-ID, X-Spam headers and the presence of List-Unsubscribe are listed as well.
Private by construction
Headers contain addresses, internal host names and sometimes tokens. This page parses them with JavaScript in your browser: the text you paste is not sent to OrbitProbe or anywhere else, not stored and not logged. You can confirm that in the Network tab of your browser's developer tools, or use the page after disconnecting from the network.
How far to trust headers
Only the headers added by your own provider are trustworthy. Everything below the first hop that you trust was supplied by earlier servers, and a sender can insert forged Received lines to disguise the origin. Read Authentication-Results from the top-most header written by your receiving server, and treat older ones, including those carried in ARC sets, as claims by intermediaries.
Server clocks differ, so a delay of a few seconds, or a small negative one, means nothing. The analyzer shows negative delays as they are rather than hiding them.