Email Header Analyzer
Paste email headers to analyze authentication and delivery path
Use the free email header analyzer when emails land in spam, get bounced, or fail authentication. Paste a full raw header to inspect the Received routing chain, SPF/DKIM/DMARC pass-fail, relay hops, and any header tampering. It is written for email admins, senders, and postmasters debugging bounce or spam-filtering problems, helping you spot missing authentication records, misconfigured SPF/DKIM selectors, and excessive relay hops.
Gmail:
- Open the email you want to analyze
- Click the three dots menu (⋮) in the top right
- Select "Show original"
- Copy the entire content that appears
Outlook (Web):
- Open the email
- Click the three dots menu (...) next to Reply
- Select "View message source"
- Copy the headers from the popup window
Apple Mail:
- Select the email
- Go to View → Message → All Headers
- Or use keyboard shortcut: Shift+Cmd+H
- Copy the visible headers
Thunderbird:
- Open the email
- Press Ctrl+U (or Cmd+U on Mac)
- Or go to View → Message Source
- Copy the headers from the source view
Email headers contain metadata about an email's journey from sender to recipient. They include routing information, authentication results, and security checks that help identify delivery issues and verify email authenticity.
Key Header Categories:
Track the email's path through mail servers (Received, Return-Path)
Verify sender identity and email integrity (DKIM, SPF, DMARC)
Basic email information (From, To, Subject, Date)
Spam filtering and security scan results
SPF (Sender Policy Framework)
SPF allows domain owners to specify which mail servers are authorized to send emails on behalf of their domain. It helps prevent email spoofing.
DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to emails, allowing recipients to verify that the email content hasn't been tampered with during transit.
DMARC (Domain-based Message Authentication)
DMARC builds on SPF and DKIM to provide policy-based authentication. It tells receiving servers what to do with emails that fail authentication.
ARC (Authenticated Received Chain)
ARC preserves authentication results when emails are forwarded through intermediary servers like mailing lists or forwarding services.
Authentication Failures
- Check SPF record syntax and authorized servers
- Verify DKIM key configuration and selector
- Ensure DMARC policy alignment settings
- Monitor authentication reports for patterns
Delivery Issues
- Review routing path for delays or loops
- Check for blacklist listings
- Verify DNS configuration and propagation
- Analyze spam score factors
Missing Headers
- Ensure email client shows full headers
- Check if headers were stripped by forwarding
- Verify mail server configuration
- Look for headers in email source/raw view
For Email Administrators:
- Implement SPF, DKIM, and DMARC authentication
- Monitor authentication reports regularly
- Use consistent mail server configurations
- Implement proper TLS encryption
- Set up reverse DNS (PTR) records
For Troubleshooting:
- Always check full headers, not just visible content
- Look for patterns in authentication failures
- Trace the routing path for delivery issues
- Compare headers from successful vs. failed emails
- Use header analysis tools for complex issues
Security Considerations:
- Be cautious when sharing headers (may contain sensitive info)
- Verify sender authenticity through multiple authentication methods
- Monitor for suspicious routing patterns
- Check for signs of email spoofing or phishing
- Validate SSL/TLS usage in email transmission
Related Tools
Need Help?
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
About Our Tools
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
