Back to Toolkit

Email Header Analysis

Deconstruct and analyze email headers to uncover the technical journey and potential spoofing indicators of any message.

1 Paste Headers
2 Analyze
3 View Results
Try sample headers
Paste headers here
or use "Try sample headers" above
0 characters
How to Get Headers
  1. Open the Admin Portal
  2. Go to Message Trace, Mail Query, then Email Lifecycle
  3. Click the icon on the message
  1. Open the email message
  2. Click the three dots menu
  3. Select "Show original"
  4. Copy the full header text
  1. Open the email, click File > Properties
  2. Or double-click the message
  3. Go to File > Properties
  4. Copy from "Internet headers" box
  1. Open the email message
  2. Go to View > Message > All Headers
  3. Or press ⌘⇧H
  4. Select all and copy
What We Analyze
  • Sender verification — SPF, DKIM, and DMARC authentication status
  • Routing path — every server hop with timestamps and delays
  • Threat indicators — spoofing, phishing signals, and reputation data
  • Loop detection — identifies mail routing loops automatically

What you'll get

Auth Status

SPF, DKIM, DMARC

Hop Trace

Full routing path

Threat Level

Risk assessment

Reputation

Talos, MX, VT links