Search 93+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Security Tool

Email Header Analyzer

Paste raw email headers to trace the delivery path, find the sender's real IP, check SPF/DKIM/DMARC and detect spoofing.

📧 Paste Raw Email Headers

Frequently Asked Questions

What information can I find in email headers?
Email headers contain the full routing path the email took from sender to recipient, the originating IP address, SPF and DKIM authentication results, the message ID, timestamps at each relay, and the mail software used to send the message.
How do I copy the full email headers from my email client?
In Gmail, open the email, click the three-dot menu, and select Show original. In Outlook, open the email, click File then Properties. In Apple Mail, go to View and select All Headers. Copy the entire header block and paste it into the analyzer.
Can email headers be forged?
The From header and some other fields can be forged by senders, which is how phishing emails appear to come from legitimate organisations. However, Received headers added by mail servers along the delivery path are harder to fake, and DKIM signatures cryptographically verify the sending domain.
What are email headers?
Email headers are metadata attached to every email that record the journey of the message from sender to recipient. They include the sending server's IP address, timestamps, mail server hops and authentication results.
What is SPF, DKIM and DMARC?
SPF (Sender Policy Framework) verifies the sending server is authorised for the domain. DKIM (DomainKeys Identified Mail) uses cryptographic signatures to verify the message hasn't been tampered with. DMARC ties SPF and DKIM together and tells mail servers what to do if checks fail.
Can I find the sender's real IP from email headers?
For emails from Gmail, Outlook and other major providers your real IP is hidden. However emails sent from some mail clients, corporate servers or less privacy-conscious providers may include your real IP in the Received headers.
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

Reading an email's hidden headers

Every email carries a block of headers you normally never see. They record who sent it, which servers handled it and whether it passed authentication checks. They are the most reliable way to tell a genuine message from a phishing attempt, and to find out why a message arrived late. Paste the full headers here to have them broken down.

Getting the full headers

What to check

What headers cannot prove

Anything added before the message reached a trustworthy server can be forged. Trust only the Received lines added by your own mail provider and the authentication results it recorded. If a message passes every check but still asks for money, passwords or urgent action, confirm it through a separate channel. To check your own domain's protection, use the SPF and DMARC checker.

Related Tools

✉️
SPF and DMARC Checker
Validate mail authentication
🔎
DNS Lookup
Check MX and TXT records
🚫
IP Blacklist Checker
Check if a sending IP is listed
🌍
IP Lookup
Geolocate a sending IP
🔍
WHOIS Lookup
Look up the sender domain
📡
HTTP Headers Check
Inspect HTTP response headers
Done!