Local-onlyparse · never uploaded · phishing triage
Email Header Analyzer
Paste the raw header of a suspicious email to inspect the sending path, authentication results and common spoofing indicators. Analysis happens locally in your browser.
What this checks
- From, Reply-To, Return-Path and the Received chain (hop count).
- Authentication-Results: SPF / DKIM / DMARC outcomes.
- Common spoofing signals — e.g. Reply-To differing from From, failed SPF/DKIM/DMARC.
Only the fields needed for the analysis are kept in memory; nothing is transmitted.
Related Knowledge
- How to Analyze Email Headers — read SPF, DKIM and DMARC results.
- Phishing Email Investigation Playbook — from header to verdict.
- Phishing Defense Checklist — full triage from header to containment.
- How to Analyze DNS Records — verify the claimed domain's SPF/DMARC configuration.