Email header analyzer

Paste an email’s headers to see where it really came from. The analyzer traces every server it passed through, checks SPF, DKIM and DMARC, shows whether each hop was encrypted, and flags the sender’s IP address if it is exposed.

Paste the headers or the whole original message. Only the headers are read.

Nothing leaves your browser. Nothing you paste is uploaded, saved or logged.

How do I find the headers?
Gmail (web)
Open the email, click the three dots next to Reply, choose Show original, then Copy to clipboard. Pasting the whole message is fine; only the headers are read.
Outlook (web and new Outlook)
Open the email, click the three dots, then View and View message source.
Outlook (classic for Windows)
Open the email in its own window, choose File, Properties, and copy the Internet headers box.
Apple Mail (Mac)
Open the email, then View, Message, Raw Source (Option Cmd U).
iPhone and iPad
The Mail app can’t show headers. Open the same email in your provider’s website on a computer and use the steps above.
On this page

What email headers tell you

Every email carries a block of headers above the message. You normally never see them, but they record the trip the email took. Each server that handles a message adds a Received line on top, and your own provider adds the results of its authenticity checks when the message arrives. That makes headers the best way to check whether an email is genuine, why it was slow, and whether it was protected on the way.

How to read the results

Summary

The top box sums up the route, the authentication checks, encryption and IP exposure in plain words. Green means nothing stood out. Amber means something is worth a look. Red means the email failed authentication and may not be from who it claims.

Authentication: SPF, DKIM and DMARC

  • SPF checks that the sending server is on the domain’s list of allowed senders.
  • DKIM checks a signature that proves the domain sent the message and nothing was changed on the way.
  • DMARC ties it together: it passes only when the domain in the From address is the one that passed SPF or DKIM. This is the result that matters most for spotting a forged sender.

Sender details

Return-Path is where bounces go. It often uses a different domain for newsletters, which is normal. Reply-To is where your reply goes; a different domain here is a classic phishing trick. The Message-ID domain usually matches the sender or their email provider.

Route and encryption

Received lines are written newest first, so the analyzer flips them into a timeline from the sender to you. For each hop it shows which server handed the message to which, the protocol, and the time since the previous hop. A protocol ending in S, such as ESMTPS, or a listed TLS version means that hop was encrypted. Hops inside one provider’s own network are marked separately, since they never cross the open internet.

IP address exposure

Some mail setups record the IP address of the device the sender wrote the email on, in an X-Originating-IP header or the first Received line. That address can reveal their rough location and internet provider. The analyzer lists any it finds.

Checking a suspicious email

Paste the headers and look at three things: did DMARC pass, does Reply-To match the sender, and does the route start at servers that belong to the company in the From line? If DMARC fails on an email asking you to pay, log in or open an attachment, treat it as fake.

Private email by default

Secria Mail removes tracking pixels automatically and senders never see your IP address. It is free, encrypted, and works on the web, iPhone and Android.

Questions about email headers

What can email headers tell you?

Headers show the route an email took, with every server it passed through and when. They also show whether the sender passed SPF, DKIM and DMARC checks, where replies and bounces go, which app sent it, and sometimes the sender’s IP address.

How do I view email headers in Gmail or Outlook?

In Gmail, open the email, click the three dots next to Reply and choose Show original. In Outlook on the web and the new Outlook, click the three dots, then View and View message source. In classic Outlook for Windows, open the email and go to File, then Properties, and copy the Internet headers box.

Can email headers show the sender’s IP address?

Sometimes. Big webmail services usually leave out the IP address of the person who wrote the email. Other providers and some desktop mail setups add it in an X-Originating-IP header or in the first Received line. The analyzer flags it when it is there.

What do SPF, DKIM and DMARC mean?

SPF checks that the server that sent the email is allowed to send for that domain. DKIM checks a digital signature showing the domain sent the message and it was not changed on the way. DMARC checks that the domain in the From address is the one that passed, and tells receivers what to do when it fails.

How can I tell if an email is fake from its headers?

Warning signs are a DMARC or SPF fail, a Reply-To address on a different domain from the sender, and a route through servers that have nothing to do with the company named in the From line. One odd detail alone is not proof, but a DMARC fail on an email asking for money or a password is a strong reason not to trust it.

Is it safe to paste my email headers here?

Yes. The analyzer runs in your browser and nothing you paste is uploaded, saved or logged. You can even disconnect from the internet after the page loads and it still works.

Email that doesn’t report back.

Secria Mail removes tracking pixels automatically and senders never see your IP address.

Start free

Explore Secria Mail