Processed in your browser

Email header analyzer

Paste raw email headers to explain delivery hops and authentication evidence. Analysis stays in this browser and does not claim that a message is absolutely safe.

Your input stays local
This work area does not upload, persist or send your input to analytics. Clear the page when you finish.

Paste headers only, not the email body or attachments.

0 / 65536 bytes

How to read the result

Received fields describe servers that handled a message. SPF, DKIM and DMARC results are reported claims from those systems. Compare the route and domains with the context in which you received the message.

How the three mechanisms fit together

SPF focuses on the sending path, DKIM on signed content, and DMARC on alignment with the visible From domain plus policy. Receivers combine these with reputation, filtering and local policy.

spf

Checks whether a sending server is authorized for an envelope domain.

dkim

Checks a cryptographic signature added by a signing domain.

dmarc

Applies alignment and domain policy using SPF and/or DKIM results.

Limits and responsible use

Headers can be forged or incomplete. This analyzer performs no DNS lookups, reputation checks or malware scanning and must not be used as the only safety decision.

Local processing

The text is processed only after you click Analyze. It is not written to the URL, storage, analytics or a server request. Clear the page when finished.

Frequently asked questions

Does this tool send my input to a server?

No. The tool runs in this browser after you choose to use it. Your pasted content or generated result is not added to URLs, storage, analytics or server requests.

Does a clean result guarantee that an email or account is safe?

No. These tools explain technical clues and reduce routine risk, but they cannot replace your judgment, malware protection, account security controls or advice from a qualified security professional.

Related privacy tools

Email link and tracker checker

Inspect pasted email HTML for risky links, hidden images and remote tracking clues without rendering it.

Secure password generator

Create strong passwords and passphrases locally using the browser cryptography API.

Base64 text encoder and decoder

Encode UTF-8 text to Base64 or decode Base64 text locally without uploading it.

URL encoder, decoder and query inspector

Encode URL components or inspect query parameters locally without opening the address.

SHA-256 and SHA-512 text hash generator

Generate SHA-256 or SHA-512 text hashes locally with browser Web Crypto.

JSON formatter and validator

Format, minify and validate JSON locally without uploading it.

Private QR code generator

Create and download QR codes locally without sending text to a server.

Image compressor and format converter

Resize, compress and convert JPEG, PNG or WebP locally. Your image never leaves this browser.

Text counter and cleaner

Count and tidy text in this browser without uploading your content.

Email subject and preview simulator

Check how sender, subject and preview text may fit in a compact inbox row before running a real client test.

Email date and Unix timestamp converter

Translate explicit ISO 8601 timestamps, Unix seconds and Unix milliseconds while debugging delivery records.

Email verification code extractor

Paste an email to find its likely verification code and copy the best match automatically.

Email HTML to plain text extractor

Turn pasted email HTML into readable plain text without rendering active or remote content.

Email attachment size budget

Estimate how selected attachments may grow after Base64 and MIME packaging before sending an email.

Email address privacy checker

Explain what an email address may reveal from its visible structure without verifying, contacting or uploading it.