Free toolAPI available

Email header analyzer

Paste or upload an email source to trace its delivery path, read authentication results, and spot signs of spoofing or deliverability problems.

Loading tool access...

interacjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunioninteracjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunion

What the analyzer checks

Every analysis turns the raw message source into a structured report

Message details

Read the sender, recipients, subject, date, Return-Path, Message-ID, and other core fields.

Authentication results

Decode the SPF, DKIM, DMARC, and ARC results recorded by the receiving mail system.

Delivery path

Follow each server hop, compare timestamps, and identify where a message was delayed.

When to analyze an email header

When a message lands in spam:

Check whether authentication failed or the receiving system recorded an anti-spam verdict

When a sender looks suspicious:

Compare the visible sender with the Return-Path, signing domain, and reported authentication identities

When delivery is delayed:

Review the timestamp on each hop to pinpoint the server where the delay occurred.

When forwarding breaks auth:

See whether forwarding changed the message or caused SPF or DKIM alignment to fail

Integrate header analysis into your workflow

Analyze headers with our API.

What an email header can tell you

How the message was handled

Headers can show server hops, timestamps, message identifiers, and authentication verdicts.

Whether the identities align

You can compare the visible sender, envelope sender, and DKIM signing domain for inconsistencies.

Where to investigate next

Failures and routing anomalies can point to configuration, forwarding, or receiving server issues.

How to read an email header

From
The address displayed as the message author. It should not be treated as proof of identity by itself.
Reply-To
The address a mail client normally uses when the recipient replies. A different Reply-To address is not automatically malicious, but it may deserve review.
Return-Path
The envelope address used for delivery failures and SPF-related processing. It can differ legitimately from the visible From address.
Received
A trace field added as mail passes through servers. Read the trusted chain in reverse chronological order to follow the message’s route.
Authentication-Results
The receiving system’s recorded SPF, DKIM, DMARC, ARC, or other authentication verdicts. The reporting server and trust boundary matter.
DKIM-Signature
The signing domain, selector, algorithm, signed fields, body hash, and cryptographic signature attached by the sender.
Message-ID
A message identifier normally generated by the sending system. It is useful for correlation but is not proof of authenticity.

Signup for testmail.app

Automate end-to-end email testing with our APIs.

FAQ

What is an email header?

An email header is the metadata attached to every email message. It contains technical information about the sender, recipients, subject, date, message ID, mail servers that handled the message, routing path, and authentication results such as SPF, DKIM, and DMARC. Email headers are used to troubleshoot delivery issues, verify sender authenticity, identify spam, and trace how an email traveled from sender to recipient.

What does an email header analyzer do?

An email header analyzer parses raw email headers into a readable report. It extracts and explains routing information, timestamps, sender details, message IDs, and authentication results such as SPF, DKIM, and DMARC. By making technical headers easier to understand, an email header analyzer helps troubleshoot delivery issues, verify sender authenticity, investigate phishing attempts, and diagnose email authentication problems.

How do I find the full email header in Gmail?

Open the email in Gmail, select More next to the Reply button, choose Show original, and then select Copy to clipboard. The Show original window contains the complete message source.

How do I view the full email header in Outlook?

To view the full email header in Outlook, open the email and use the message details option. In new Outlook or Outlook on the web, select More actions (⋯) → View → View message details. In classic Outlook for Windows, open the email in a separate window, then select File → Properties and look for the Internet headers section. You can copy the full header and paste it into an email header analyzer to inspect routing, authentication, and delivery details.

Can an email header prove who sent an email?

No. An email header cannot definitively prove who sent an email. It provides technical information about how a message was routed, which mail servers handled it, and whether authentication checks such as SPF, DKIM, and DMARC passed. While email headers can help verify a domain, investigate phishing, and trace a message’s path, they cannot confirm the identity of the individual who sent the email, and some header fields can be forged.