1. Home
  2. Free tools
  3. Email header analyzer

Email header analyzer

Paste the raw headers of any email, or open a .eml file, and this tool shows the SPF, DKIM and DMARC results, whether the passing domains align with the From address, every server the message passed through with the delay at each hop, and any spam filter verdicts. It is free and runs in your browser, so the headers never leave your device.

Everything runs in your browser. Your headers are never uploaded or sent to our server.

How to get the full headers

Copy the headers from the recipient’s mailbox, not the sender’s Sent folder. The authentication results and most of the delivery path are only added on arrival.

  • Gmail: open the message, click More next to Reply, choose Show original, then Copy to clipboard (Google’s instructions).
  • Outlook on the web and new Outlook for Windows: select More actions at the top of the message, then View, then View message details. In classic Outlook, double-click the message to open it, choose File, then Properties, and copy the Internet headers box (Microsoft’s instructions).
  • Apple Mail on Mac: choose View, then Message, then All Headers. View, Message, Default Headers switches back (Apple’s instructions).

How to read the results

Start with the topmost Authentication-Results header, because your own provider wrote it. Every server adds its headers above the ones already there, so anything lower down came from earlier servers and anything a sender wrote can be forged. ARC-Authentication-Results headers are copies kept by forwarders and mailing lists, so the original result survives when forwarding breaks SPF or DKIM.

Then read the Received headers from the bottom up. The bottom one is the first server to accept the message and the top one is the last. The gap between two timestamps is the time the message waited at the earlier server, which is how you find the hop that held it for an hour. The protocol word matters too: ESMTPS means the connection used TLS, ESMTPA means the sender logged in, and ESMTPSA means both.

What the common results mean

dkim=pass
A signature on the message verified against the public key published by the domain in header.d, so the signed headers and body have not changed since that domain signed them. It says nothing about the From address unless that domain matches it. To inspect the key itself, run the selector through the DKIM checker.
spf=softfail
The sending IP is not in the SPF record of the envelope sender (smtp.mailfrom), and the record ends in ~all, which asks receivers to accept but mark the message. A hard spf=fail means the record ends in -all. Both usually mean a sending service is missing from the record. The SPF checker shows what is actually authorised.
dmarc=fail
Neither SPF nor DKIM passed with a domain aligned to the From address. The receiver then applies the domain’s policy: nothing for p=none, the spam folder for p=quarantine, rejection for p=reject. Check the policy with the DMARC checker.

Common problems the headers reveal

  • SPF and DKIM pass but DMARC fails. An email service is using its own bounce domain and signing with its own domain. Set up a custom return-path and DKIM on your domain in that service.
  • DKIM fails with “body hash did not verify”. Something changed the message after signing, usually a mailing list footer, a security gateway or a forwarding rule.
  • A Reply-To on another domain. Normal for help desks and some email services, and also the classic sign of a phishing message that wants your answer to go somewhere else.
  • One hop holds the message for minutes or hours. A large gap at the sender’s side points to a queue or throttling; at the receiving side it often means greylisting or content scanning.

For a full walk through a real header, see how to read email headers to debug deliverability problems. If mail is landing in spam at Gmail specifically, see why your emails go to spam in Gmail. To check a sending domain’s records all at once, run the deliverability audit.

Common questions

Is it safe to paste my email headers into this tool?
Yes. The analyzer runs entirely in your browser and the headers are never uploaded or sent to our server. Headers can still contain names, addresses and internal server names, so treat them like any other private data when you share them elsewhere.
Which Authentication-Results header should I trust?
The one added by your own mail provider, which is normally the topmost Authentication-Results header. Headers lower down were written by earlier servers, and anything above the first Received line from your provider could have been added by the sender, so it proves nothing.
What does spf=softfail mean?
The server that sent the message is not listed in the SPF record of the envelope sender's domain, and that record ends in ~all, which asks receivers to accept the message but treat it with suspicion. It usually means a sending service was never added to the SPF record.
Why does DMARC fail when SPF or DKIM passes?
DMARC needs a pass that is aligned with the From domain. SPF can pass for an email service's bounce domain and DKIM can pass for the service's own signing domain, and neither counts unless that domain matches the From domain, exactly or at the organisational level under relaxed alignment.
How do I find out why an email was delayed?
Read the Received headers from the bottom up. Each one records when a server accepted the message, so the gap between two consecutive timestamps is the time spent at the earlier server. The analyzer computes those gaps and highlights the largest. Negative gaps mean a server clock is wrong.

Headers explain what happened to one message. Bounces come from the list: to find addresses that will hard-bounce before you send, use the free email checker or see pricing for whole lists.

Ready to clean your email lists?

Start verifying emails today and boost your deliverability.

Get Started

Cancel anytime • No setup required