Web / Email
Email Header Analyzer: Route, Delays, SPF, DKIM, DMARC
Paste the raw headers of an email to see the path it took through mail servers, how long each hop took, the total delivery time, and whether it passed SPF, DKIM, and DMARC, without sending the headers anywhere.
Email Header Analyzer: Route, Delays, SPF, DKIM, DMARC: Header lines are unfolded and read in order. Received headers are listed from the oldest, at the bottom of the message, to the newest, with the time each server stamped and the delay since the previous one, flagged when it is over a minute. SPF, DKIM, and DMARC results are read from the Authentication-Results header that the receiving server added. Runs 100% locally in your browser with zero server file uploads.
- Category
- Web tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
| # | From | By | Protocol | Time | Delay |
|---|---|---|---|---|---|
| 1 | laptop.local (unknown [192.0.2.10]) | mail.example.org | ESMTPSA | 2026-10-05 10:00:02 | — |
| 2 | mail.example.org (mail.example.org [203.0.113.5]) | mx.example.com | ESMTPS | 2026-10-05 10:00:07 | 5 s |
- from
- Alex <alex@example.org>
- to
- Sam <sam@example.com>
- subject
- Project update
- date
- Mon, 05 Oct 2026 10:00:01 +0000
- message-id
- <abc123@example.org>
Each server that handles a message adds a Received header at the top, so the path is read from the bottom up; the delay column shows how long each hop took, according to the servers' clocks, which may disagree. SPF, DKIM, and DMARC results come from the Authentication-Results header added by the receiving server. A pass for all three means the message really came from the domain in the From address. The headers stay in your browser.
Reading Received headers
Each server adds its Received line above the others, so the first server to handle the message is at the bottom. Lines lower down were written by servers the sender controlled and can be forged; trust only those added by servers you know.
Fixing failures
If your own mail fails SPF or DMARC, publish or correct the records with the SPF record generator and the DMARC record generator.
How to use it
- In your email app, open the message's original or source headers and copy them.
- Paste them here.
- Read the hops, delays, and authentication results.
Privacy & limitations
The headers are analysed in your browser and never uploaded.
Related tools
Frequently asked questions
How do I get the headers?
In Gmail, open the message, choose More and then Show original; in Outlook, open the message's Properties; in Apple Mail, choose View, Message, All Headers.
What does a DMARC fail mean?
The message did not pass SPF or DKIM for the domain in its From address, so it may be spoofed, or the sender's records are misconfigured.
Why are some delays negative?
The times come from each server's clock, and clocks can be a few seconds apart.
Free tool · runs in your browser · no account required