About
Paste the raw header from a message and this pulls out the path it travelled and the authentication lines that were attached along the way. It runs in the page, which matters when the message you are examining is one you would rather not hand to a website.
How to use
Open the original message in your mail client, copy the whole header block starting at Return-Path or the first Received line, and paste it in. The body is not needed and is better left out.
Reading Received from the bottom up
Each server that handles a message adds a Received line at the top, so the oldest hop is at the bottom and the most recent is first. Reading upward follows the message forward in time. The bottom entry is the closest thing to an origin the header offers, and it is the line worth attention when the sender's claimed domain and the actual first hop disagree.
SPF, DKIM and DMARC in one glance
Authentication results are stamped by the receiving server, not by the sender, which is what makes them worth reading. SPF says whether the sending address was permitted to use that server. DKIM says whether a signature over the message validates. DMARC ties them to the visible From address. A pass on all three is unremarkable, and a fail on the last one deserves attention.
What a missing field does not mean
An absent SPF or DKIM line is not proof of forgery. It can simply mean the receiving server did not perform that check, or that the header you pasted was trimmed by the client on the way to your clipboard. Absence is a gap in the evidence rather than evidence itself, and treating it as proof produces false accusations.
Why this one runs in your browser
Headers carry addresses, internal hostnames, and message identifiers that are nobody else's business. Parsing them in the page means the text stays where you pasted it. When you are dealing with a suspected phishing message, paste the header only and leave the body out, since attachments and body content are where anything genuinely dangerous lives.
FAQ
Where do I find the raw header?
In Gmail it is under Show original. In Outlook on the web it is View message details. Desktop Outlook keeps it under message properties, which is the hardest of the three to find.
I pasted the message but there are no Received lines.
You copied what the client displays rather than the source. The header block is separate and has to be opened deliberately.
Can it tell me where the sender is?
No. Headers describe the servers a message passed through, not the person who wrote it, and the first hop is frequently a provider in another country from the sender.
Does this prove a message is phishing?
It gives you evidence rather than a verdict. Failed authentication and a path that does not match the claimed sender are strong signals, but the judgement stays yours.
Related tools
- Email tools
- Gmail Address Checker
Check up to ten Gmail addresses per run.
- Outlook Mail Reader
Read recent mail using your own refresh token.
- SMTP Test
Open a short SMTP session and read the banner.
- MX Lookup
Mail servers and priorities for a domain.
- DNS Lookup
Public A, AAAA, CNAME, MX, TXT and NS records.