Skip to content
ToolsOnDuty - free online tools
Security & Cryptography

Email Header Analyzer

Explain email routes, reported SPF/DKIM/DMARC results and common phishing signals locally.

Free foreverRuns in your browserNo sign-up

100% private - runs entirely in your browser.

Your input, keys and passwords are never uploaded. Want proof? Load this page, then turn off your internet - the tool still works. For an exact check, open your browser's DevTools Network tab and confirm no data is sent when you use it.

About the Email Header Analyzer

Raw email headers describe how a message travelled, which domains handled it and what authentication verdicts the receiving system reported.

This analyzer parses the pasted header block locally. It highlights reported authentication failures and sender-domain mismatches without uploading the message or calling a reputation service.

Header analysis is evidence, not a guarantee. Attackers can add misleading headers, and cryptographic verification requires the original message plus current DNS data.

Key features

  • Local raw-header parsing
  • Reported SPF, DKIM and DMARC summary
  • From, Reply-To and Return-Path comparison
  • Received-hop ordering
  • Transparent limitations with no safety guarantee

How to use

  1. 1Open the original message source or Show original view in your email provider.
  2. 2Paste the complete header block and select Analyze headers.
  3. 3Review warnings alongside the actual message context before taking action.

Examples

Review authentication results
Input: Authentication-Results: spf=pass; dkim=pass; dmarc=pass
Output: Reported pass results with limitations

Frequently asked questions

Does this prove that an email is safe?
No. It explains supplied headers but does not independently verify DNS, signatures, links or attachments.
Are the headers uploaded?
No. Analysis runs locally in the browser.
Why can From and Return-Path differ?
Email platforms often use a separate bounce domain, so a mismatch is a review signal rather than automatic proof of phishing.