Free Email Header Analyzer
Paste the raw headers from a suspicious email to check SPF/DKIM/DMARC results and spot spoofing signs, explained in plain language.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the Header Analyzer
Get the raw headers
Open the suspicious email in Gmail or Outlook and copy its full raw headers (see below for exact steps).
Paste and analyze
Drop them into the box below and click Analyze – nothing is saved to an ActiScan account.
Read the plain-language result
SPF/DKIM/DMARC pass-or-fail, any spoofing signs, and a one-line verdict.
What Your Result Means
SPF / DKIM / DMARC: passGood signThe receiving mail server's own Authentication-Results header confirms the message passed authentication for that sender domain – a strong signal it wasn't spoofed in transit.
SPF / DKIM / DMARC: failWarning signOne or more authentication checks failed. Combined with a mismatched From/Return-Path domain or an unusual Received chain, this is a strong phishing indicator.
Overall verdict: suspiciousCautionThe analysis ends with a one-line call of legitimate or suspicious, based on authentication results plus routing signs – treat a suspicious verdict as reason not to click anything in the message.
What is Email Header Analysis?
Every email carries a set of headers most inboxes hide by default – technical metadata added by every mail server the message passed through on its way to you. Read together, they reveal whether the sending domain actually authenticated the message (SPF, DKIM, DMARC), what path it took to reach you (the Received chain), and where it actually originated, as opposed to who it claims to be from.
This tool reads the raw headers you paste and uses AI to translate that technical detail into a plain-language explanation: whether SPF, DKIM, and DMARC each passed or failed, any signs of spoofing or unusual routing, and a one-line verdict on whether the message looks legitimate or suspicious.
Key Header Fields Explained
| Header | What it shows | Example |
|---|---|---|
| Authentication-Results | The receiving mail server's own SPF, DKIM, and DMARC verdicts for the message. | dkim=pass header.i=@example.com; spf=pass; dmarc=pass (p=REJECT) |
| Received | One line per server hop the message passed through, oldest at the bottom – an unexpected or foreign hop can be a red flag. | Received: from mail.example.com (mail.example.com [203.0.113.5]) |
| From | The display sender. Compare it against the Return-Path and the DKIM/SPF-authenticated domain – a mismatch is a spoofing signal. | From: Sender Name <noreply@example.com> |
| Return-Path | Where bounce messages actually go. Attackers often set this to a domain that doesn't match the visible From address. | Return-Path: <bounce@example.com> |
How to Get Raw Headers from Gmail or Outlook
Gmail
Open the email, click the three-dot menu (⋮) next to Reply, then choose Show original. Copy the text shown, or use the page's Copy to clipboard button.
Outlook (desktop)
Open the email in its own window, go to File → Properties, and copy the text from the Internet headers box.
Outlook (web)
Open the email, click the three-dot More actions menu, then View → View message source and copy the headers from the top of what opens.
Next Steps After Your Analysis
Verdict suspicious?
Don't click any links or reply. If it contained one, check it separately before deciding it's safe.
Check a link in the message →Own the domain being spoofed?
A one-off header check tells you about a single message – a DMARC policy protects every message going forward.
Check your DMARC record →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this header analyzer free?
Yes – paste headers and analyze them for free, no signup required.
What does this tool actually do with what I paste?
The headers you paste are sent to an AI model to generate the plain-language analysis shown back to you here – they aren't saved to an ActiScan account.
Why does it say the tool isn't configured?
This tool needs an AI provider key set up on the deployment it's running on. If that isn't configured, the form is hidden and this message shows instead.
Does this replace the DMARC/SPF checker?
No – this analyzes headers from one specific message you already received. The DMARC and SPF checkers look at a domain's published DNS policy going forward.
Can I paste headers from any email provider?
Yes – any raw header text works, including from clients other than Gmail or Outlook, as long as it includes the standard header fields.