Free email-authentication toolkit

Free email header
analyzer.

Paste the full headers of a message and get the DMARC verdict, why it came out that way, the delivery path and every header — no signup, no backend.

100% in your browser Nothing is uploaded Always free

Email header analyzer

Paste the full headers of a message — Gmail's Show original, Outlook's Message source. You will get the DMARC verdict, why it came out that way, the delivery path and every header.

100% in your browser · nothing is uploaded. We stop reading at the first blank line, so the message body is never parsed.

The basics, briefly

Reading email headers explained

Where do I find my email headers?

Gmail: open the message → Show original. Outlook / Microsoft 365: open the message → FilePropertiesInternet headers. Apple Mail: ViewMessageAll Headers. Copy everything from the top down to the first blank line.

Is my email uploaded anywhere?

No. The analysis runs entirely in your browser; nothing is sent to a server. The parser stops at the first blank line, so the message body is never read at all.

Why does it say SPF passed but DMARC failed?

DMARC needs more than a pass: the domain that passed has to align with the domain in the From: header. A message sent through a provider often passes SPF for the provider's own domain, which is not yours. Read more: DMARC alignment explained.

What does "not enough information" mean?

It means this header does not contain the receiver's own verdict for one of the two checks, and we will not guess. A DKIM-Signature header shows a signature exists but not whether it verified — only the receiving server can say that, in Authentication-Results.

More free tools