Email Header Analyzer
Paste raw email headers to trace the delivery path, find the sender's real IP, check SPF/DKIM/DMARC and detect spoofing.
Frequently Asked Questions
What information can I find in email headers?
Email headers contain the full routing path the email took from sender to recipient, the originating IP address, SPF and DKIM authentication results, the message ID, timestamps at each relay, and the mail software used to send the message.
How do I copy the full email headers from my email client?
In Gmail, open the email, click the three-dot menu, and select Show original. In Outlook, open the email, click File then Properties. In Apple Mail, go to View and select All Headers. Copy the entire header block and paste it into the analyzer.
Can email headers be forged?
The From header and some other fields can be forged by senders, which is how phishing emails appear to come from legitimate organisations. However, Received headers added by mail servers along the delivery path are harder to fake, and DKIM signatures cryptographically verify the sending domain.
What are email headers?
Email headers are metadata attached to every email that record the journey of the message from sender to recipient. They include the sending server's IP address, timestamps, mail server hops and authentication results.
What is SPF, DKIM and DMARC?
SPF (Sender Policy Framework) verifies the sending server is authorised for the domain. DKIM (DomainKeys Identified Mail) uses cryptographic signatures to verify the message hasn't been tampered with. DMARC ties SPF and DKIM together and tells mail servers what to do if checks fail.
Can I find the sender's real IP from email headers?
For emails from Gmail, Outlook and other major providers your real IP is hidden. However emails sent from some mail clients, corporate servers or less privacy-conscious providers may include your real IP in the Received headers.