Email Header Analyzer logo

Prescosoft

Email Header Analyzer

Open Tool
100% in your browser — no uploads

Email Header
Analyzer

Paste any email header and get a plain-English spoofing analysis: SPF, DKIM & DMARC verdicts, the full server path, and red flags — decoded privately on your device.

Analyze a Header Free forever · No account · No watermark
Nothing is uploaded SPF · DKIM · DMARC Hop-by-hop timeline No account needed

Paste the email header

In Gmail: open the message → ⋮ → Show original, copy everything. Outlook web: ⋯ → View → View message source. Apple Mail: View → Message → Raw Source.

How it works

Three layers of forensic reading, all done locally.

1

Decode the journey

Received headers are read bottom-up (oldest first), so the hop timeline shows every server and the delays between them — fast chains hint at automated bulk sending.

2

Check the authentication

SPF, DKIM, and DMARC verdicts are extracted from Authentication-Results — the receiving server's own record of whether the sender was authorized.

3

Score the risk

Cross-checks (envelope vs. visible sender, Reply-To, brand impersonation) combine into a 0–100 risk score with a plain-English verdict.

Why Prescosoft Email Header Analyzer

  • The header never leaves your device — analysis is 100% local JavaScript.
  • Plain-English explanations, not raw regex dumps.
  • Free, no account, no limits, no watermarks.
  • Works offline after the page loads.

Typical online header analyzers

  • Upload your header to their server — ironic for security forensics.
  • Ad-heavy pages with poor, outdated SEO (r/sysadmin's top complaint).
  • Raw technical output with no plain-English guidance.
  • Require accounts or gate features behind signups.

Who is this for?

🛡️

Suspicious-email triage

Got a "your account is limited" or invoice mail that feels off? Paste the header before clicking anything — the verdict appears in seconds.

🧑‍💻

IT & sysadmin forensics

Trace where a phishing attempt originated, verify spoofing claims, and document the evidence — without uploading the header to a third party.

🎓

Security training & learning

The sample header and plain-English explanations make SPF, DKIM, and DMARC tangible for students and non-technical teams.

Frequently Asked Questions

What is an email header analyzer?
Every email carries hidden metadata called headers that record the message's journey: which servers handled it, when, and whether authentication checks (SPF, DKIM, DMARC) passed. An analyzer decodes that raw text into something readable and flags signs of spoofing — like a display name impersonating a brand, an envelope sender that doesn't match the visible From address, or failed authentication checks.
Is it safe to paste my email headers here?
Yes — because nothing leaves your device. The analysis runs entirely in your browser with plain JavaScript. Your headers are never uploaded, stored, or transmitted anywhere, and the tool works offline after the page loads. That matters for security forensics: the whole point is to inspect potentially malicious mail without sharing it with yet another service.
How do I find the full headers in Gmail?
Open the email, click the three-dot menu (⋮), choose 'Show original', and copy everything from the new tab — or use 'Download original' to get the raw message. Paste the whole thing into the analyzer. Outlook: open the message, click the ⋯ menu → View → View message source (web) or double-click → File → Properties → Internet headers (desktop). Apple Mail: open the message, View → Message → Raw Source.
What do SPF, DKIM, and DMARC mean?
They are the three email authentication standards: SPF verifies the sending server is authorized to send for the claimed domain, DKIM verifies the message was signed by the domain and not tampered with, and DMARC ties them together by telling receiving servers what to do when both fail. A pass on all three makes spoofing unlikely; failures don't always mean spam (forwarding and mailing lists break them), but combined with other red flags they are a strong warning.
What are the most common signs of a spoofed email?
The big ones: a display name that impersonates a well-known brand or person while the actual address is unrelated; a Reply-To or Return-Path domain that differs from the From domain; SPF or DMARC failures; urgent language demanding credentials or payments; and a message ID or sending server that doesn't match the claimed sender. One red flag is worth a closer look; several together mean treat it as an attack.
Does the analyzer check live DNS records?
No — and that's deliberate. The tool is fully client-side, so it never makes network calls (that would both leak the header and require a backend). Instead it reads the authentication verdicts that the receiving mail server already recorded in the Authentication-Results header, plus structural clues in the Received chain. It gives you a strong forensic read without ever sending your data anywhere.

Related guides

Checksum Calculator

How to Verify a File's Checksum

Confirm downloads haven't been tampered with — the same verification mindset, applied to files instead of mail.

Read guide
CSV Cleaner

How to Clean a CSV File (Without Uploading It Anywhere)

Keep your data private while you work with it — the same principle as this analyzer.

Read guide

More Prescosoft tools

🧬

Checksum Calculator

Verify file integrity.

🛡️

StegoCrypt Image Vault

Hide data in images.

🔐

Password Generator

Strong passwords & passphrases.

🔄

Local File Converter

Convert files privately.

Check that suspicious email — privately

Full spoofing analysis with zero uploads. Your headers never leave your device.

Analyze a Header Now