Paste any email header and get a plain-English spoofing analysis: SPF, DKIM & DMARC verdicts, the full server path, and red flags — decoded privately on your device.
In Gmail: open the message → ⋮ → Show original, copy everything. Outlook web: ⋯ → View → View message source. Apple Mail: View → Message → Raw Source.
Three layers of forensic reading, all done locally.
Received headers are read bottom-up (oldest first), so the hop timeline shows every server and the delays between them — fast chains hint at automated bulk sending.
SPF, DKIM, and DMARC verdicts are extracted from Authentication-Results — the receiving server's own record of whether the sender was authorized.
Cross-checks (envelope vs. visible sender, Reply-To, brand impersonation) combine into a 0–100 risk score with a plain-English verdict.
Got a "your account is limited" or invoice mail that feels off? Paste the header before clicking anything — the verdict appears in seconds.
Trace where a phishing attempt originated, verify spoofing claims, and document the evidence — without uploading the header to a third party.
The sample header and plain-English explanations make SPF, DKIM, and DMARC tangible for students and non-technical teams.
Confirm downloads haven't been tampered with — the same verification mindset, applied to files instead of mail.
Read guide CSV CleanerKeep your data private while you work with it — the same principle as this analyzer.
Read guideFull spoofing analysis with zero uploads. Your headers never leave your device.
Analyze a Header Now