Free tools
Email header decoder
Paste the raw headers (in most clients: “Show original” or “View source”). Parsing happens in your browser — nothing is uploaded or stored.
Raw headers
How to read the results
SPF says whether the sending server was authorized by the domain. DKIM says whether the message signature is intact. DMARC says whether either of those aligns with the visible From domain — that alignment is what stops impersonation. A Reply-To or Return-Path on a different domain than From is one of the most reliable tells in business-email-compromise attempts.
Definitions live in the glossary; to score the message body itself, use the phishing checker.