Paste the full headers of a suspicious email and see what they actually say.
This is processed entirely in your browser. We don't send the headers to any server or store them — you can paste a work email with confidence.
Email headers contain the complete technical routing history of a message, from origin SMTP server to the destination mailbox.
Inspecting these headers verifies SPF, DKIM, and DMARC authentication protocols to detect sender spoofing and targeted phishing attacks.
In Gmail, click More (three dots) -> Show original. In Outlook, open Message Properties and copy Internet headers.
No. Header analysis occurs strictly in-memory and no sender or message body data is ever retained or shared.
If your SPF or DMARC are misconfigured, anyone can send email spoofing your domain. Check it for free.