Security

Phishing Email Header Analyzer

Paste raw email headers to trace the delivery path, read the SPF, DKIM and DMARC results, spot display name spoofing and header mismatches, and see where a message actually originated.

Last reviewed by the Radiatus Cloud team

Analysis appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

The headers say more than the message body

A phishing message is written to be convincing. Its headers are written by mail servers and are much harder to fake consistently. The Received chain records every hop in reverse order, the Authentication-Results header records what the receiving server concluded about SPF, DKIM and DMARC, and the relationship between the From header, the envelope sender and the DKIM signing domain reveals alignment failures that no amount of visual polish can hide.

Authentication results are the first thing to read

SPF checks whether the sending IP is authorised for the envelope sender domain. DKIM verifies a cryptographic signature over the message. DMARC requires at least one of those to pass and to be aligned with the visible From domain. A message from a well known brand where DMARC fails is either spoofed or misconfigured, and for any large organisation with a mature email programme the first explanation is far more likely. A DMARC pass, conversely, does not make a message safe: it proves the sender controls the domain, and attackers register domains.

The tricks that survive authentication

Display name spoofing puts a trusted name in the From header with an unrelated address behind it, and passes every authentication check because the attacker owns the sending domain. Lookalike domains substitute characters or add a plausible word. Reply-To pointing somewhere different from the From address routes the conversation to the attacker after the first reply. All three are visible in the headers and invisible in most mail clients, which show only the display name.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

How do I get the raw headers?

In Gmail, open the message and choose Show original. In Outlook, File then Properties, or View message source in the web client. In Apple Mail, View then Message then Raw Source. Copy everything above the message body.

Does a DMARC pass mean the message is safe?

No. It proves the sender is authorised to use the domain in the From header. An attacker who registers a lookalike domain and configures SPF and DKIM correctly passes DMARC on their own domain. Authentication answers who sent it, not whether to trust them.

Which Received header shows the real origin?

The bottom one is the earliest hop and usually closest to the origin, but only the headers added by servers you trust are reliable. Anything below your own infrastructure was written by systems the attacker may control and can be entirely fabricated.

What is alignment and why does it fail?

DMARC requires the SPF or DKIM domain to match the visible From domain. A message sent through a marketing platform often passes SPF for the platform domain while the From header shows yours, which is an alignment failure. This is the most common reason legitimate mail fails DMARC.

Is it safe to paste real headers here?

Analysis runs entirely in your browser and nothing is transmitted. Headers do contain internal hostnames, IP addresses and recipient addresses, so treat the content as sensitive regardless.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste the full raw headers of a suspicious message to analyse its authentication and path.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.