Email Header Analyzer
Review pasted email headers, unfold continuation lines and inspect a reported delivery timeline. Summarize declared SPF, DKIM and DMARC results with masked routing identities and JSON/text/CSV exports.
Settings
Try the example or enter your own settings.
Headers are untrusted reported data. No SPF/DKIM/DMARC verification, DNS, mailbox connection or sending. Dates support a conservative numeric-zone subset; legacy zones and leap seconds are unresolved. Raw personal header values are omitted, but advertising scripts can technically access pasted input. Use synthetic examples.
Using Email Header Analyzer
Review pasted email headers, unfold continuation lines and inspect a reported delivery timeline. Summarize declared SPF, DKIM and DMARC results with masked routing identities and JSON/text/CSV exports.
- Paste only synthetic or public email headers, or open a UTF-8 text/EML sample. The first blank header/body separator ends analysis.
- Analyze the report. Received fields are shown bottom-first, with explicit-zone UTC times and adjacent timestamp differences. Expand the declared authentication summary.
- Review unresolved dates or negative deltas, then copy/download JSON or text. CSV exports the timeline; keep routing masking enabled when sharing a report.
Example
Try the included editable example. Analyze the report. Received fields are shown bottom-first, with explicit-zone UTC times and adjacent timestamp differences. Expand the declared authentication summary.
Questions & answers
Does this connect to my email account?
No. It only analyzes manually supplied text in a local worker. It does not fetch DNS records, connect to a mailbox, read messages or send email.
Does SPF/DKIM/DMARC pass prove the email is genuine?
No. The tool summarizes method=result claims in Authentication-Results. Such headers can be forged outside the recipient trust boundary. It does not validate signatures, SPF authorization, DMARC alignment or ARC seals.
How is the delivery timeline ordered?
Received headers are reversed from source order, so the bottom field is shown first. They are not sorted by timestamp. Adjacent parsed UTC timestamps yield estimated differences; clock skew, forged headers and nonstandard ordering can make them negative or misleading.
Which date formats are supported?
English month names, four-digit years from1900, valid calendar/time and numeric ±HHMM zones, optional weekday and seconds. -0000 is represented as UTC with unknown original local zone. Legacy named zones, obsolete two-digit years and leap seconds remain unresolved.
What is omitted or masked?
Address fields, subjects, message IDs, queue IDs, authentication properties, signatures and raw header values are not exported. From/by routing tokens are masked by default; a public-sample mode can show simple host/IP tokens. Header names/counts, timestamps, known protocol tokens and declared authentication methods/results remain visible.
What input and parsing limits apply?
100,000 characters,500 header fields,100 Received fields and20 comment levels. Continuation lines are unfolded. Text after the first blank header/body separator is ignored. Routing supports simple from/by/with tokens; extended routes and some authentication syntax are outside scope. JSON/text include authentication summaries; CSV contains only the timeline.
Help improve this tool
Report a problem or suggest an improvement
Describe the issue without pasting private tool input. Feedback goes to our admin inbox.
