Email Header Privacy Analyzer
Paste email headers to detect tracking bits, SPF, DKIM, and IP leaks.
Last reviewed by the Radiatus Cloud team
Open email > "Show Original" / "View Headers" > Paste here.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
See what an email header reveals
Email headers carry a lot beyond the subject and sender, including tracking signals, authentication results and IP information. This tool lets you paste email headers to detect tracking bits, the SPF and DKIM authentication results, and IP leaks, so you can see what a message reveals about its origin and about you.
What the headers tell you
Headers record the path a message took and the checks it passed. SPF and DKIM results tell you whether the sender is authenticated, which is central to spotting spoofing and phishing. Received headers can expose IP addresses along the route. Tracking elements reveal whether the sender is monitoring opens. Reading these turns an opaque message into evidence: is it really from who it claims, and what is it trying to learn about you. That is a genuinely useful skill for spotting phishing.
Read the evidence
The tool runs entirely in your browser, so nothing you paste is uploaded, which is exactly what you want when the input is your own security-sensitive data.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What do SPF and DKIM results tell me?
Whether the sender is authenticated. A failing SPF or DKIM result is a strong signal of spoofing, which is central to spotting phishing.
What can email headers leak?
IP addresses along the delivery path, tracking signals that reveal whether opens are monitored, and clues about the sending infrastructure.
How does this help spot phishing?
By showing whether a message is really from who it claims. Authentication failures and suspicious routing are evidence a message is not genuine.
What are tracking bits?
Elements that let a sender know when and where you opened a message. Detecting them reveals whether the email is monitoring you.
Are my headers uploaded?
No. The analysis runs entirely in your browser.
Privacy & Security
Headers processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.