Skip to content
praneeth.me

praneeth@website:~$ headers --trace [beta]

Email header analyser

Paste the full header block — Outlook’s View message details, Gmail’s Show original, or the raw source; a body after it is ignored. Read in your browser; never sent anywhere.

try:

A message’s headers record what every server that handled it saw. The receiver’s Authentication-Results line says whether SPF, DKIM and DMARC passed, but not why — and the why is almost always alignment: which domain actually passed, and whether it’s the one in the From address. This lays that out, walks the route hop by hop, reads each DKIM signature’s tags, and decodes Microsoft 365’s anti-spam stamps.

standards
RFC 8601 · 6376 · 9989 · 8617
reads
Outlook · Gmail · Microsoft 365 · raw source
what's collected
nothing

Nothing you paste is sent anywhere. Headers carry names, addresses, internal server names and IP addresses, so parsing happens in your browser and the paste is never stored or put in the URL. There is no server, no analytics and no lookup of any kind — once this page has loaded it makes no network requests at all. That also means it doesn’t re-verify signatures or look up DNS: it reads what the receiving server recorded, and checks it against the RFCs.

# getting the headers

Use the copy in the recipient’s mailbox. A copy from Sent Items was never received over SMTP, so it carries no receiver’s results.

# what it can’t do

For what a domain publishes in DNS — the SPF record, DKIM keys, the DMARC policy — use domain --health. To build or check a DMARC record, dmarc --check. ARC (RFC 8617) is an Experimental RFC; its results are shown as receivers record them.