Paste the raw headers of any email to reconstruct its journey, see how long each hop took and read the SPF, DKIM and DMARC verdicts. Everything is parsed locally — nothing is sent anywhere.
Every email carries a block of headers above the message body. They record where the message came from, every server it passed through, when each handoff happened and the results of authentication checks. Most of this is hidden by default, but it is the first place to look when you investigate a suspicious message, a delivery delay or a spam-folder problem.
This analyzer reads those headers and turns them into a readable timeline: the delivery path from the sending server to the inbox, the delay at each hop, the SPF, DKIM and DMARC verdicts and the key fields such as From, Subject and the originating IP address.
Copy everything from the first Received or From line down, and paste it into the box above.
SPF confirms that the sending server is allowed to send for the envelope domain. DKIM confirms that the message carries a valid cryptographic signature and was not altered. DMARC ties them together and checks that the authenticated domain matches the visible From address. A healthy message usually shows pass for all three.
A failure is not always malicious — mailing lists and forwarders often break SPF or DKIM — but a DMARC failure combined with a mismatched Reply-To is a classic sign of a spoofing or phishing attempt worth investigating.
Email headers can contain personal information, so this tool never sends them anywhere. The headers are parsed within your session and are not stored, logged or forwarded. To test your own mail end to end, send a message to a free TempBox temporary address and analyze the headers it receives.
It reads the technical headers of an email and presents them in a readable form: the chain of servers the message passed through, the delay at each hop, the SPF, DKIM and DMARC results and the originating IP address.
In Gmail choose “Show original”, in Outlook open File → Properties and copy the Internet headers, in Apple Mail use View → Message → All Headers. Then paste everything into the box above.
The delivery path shows the delay at each hop. A large delay at one step usually points to greylisting, a queued or overloaded server, or a slow spam filter on the receiving side.
It means the message did not pass that authentication check. It can be a misconfiguration, a forwarded or mailing-list message, or a spoofing attempt. A DMARC failure is the most significant because it governs the visible From address.
The headers give strong clues: failed DMARC, an originating IP that does not match the claimed sender, or a Reply-To on a different domain are all warning signs. They are not definitive proof on their own, but together they are revealing.
No. The analyzer runs within your session and does not store, log or transmit the headers. They never leave your browser except to be parsed.
Yes. It is completely free, requires no registration and keeps the headers you paste private.