praneeth@website:~$ headers --trace [beta]
Email header analyser
Paste the full header block — Outlook’s View message details, Gmail’s Show original, or the raw
source; a body after it is ignored. Read in your browser; never sent
anywhere.
# findings
# authentication
# route
# microsoft 365
What Exchange Online Protection stamped on the message, decoded with Microsoft’s own descriptions. Fields Microsoft doesn’t document are left out rather than guessed at.
# message
A message’s headers record what every server that handled it
saw. The receiver’s Authentication-Results line says
whether SPF, DKIM and DMARC passed, but not why — and the
why is almost always alignment: which domain actually passed, and whether
it’s the one in the From address. This lays that out, walks the route
hop by hop, reads each DKIM signature’s tags, and decodes Microsoft
365’s anti-spam stamps.
- standards
- RFC 8601 · 6376 · 9989 · 8617
- reads
- Outlook · Gmail · Microsoft 365 · raw source
- what's collected
- nothing
Nothing you paste is sent anywhere. Headers carry names, addresses, internal server names and IP addresses, so parsing happens in your browser and the paste is never stored or put in the URL. There is no server, no analytics and no lookup of any kind — once this page has loaded it makes no network requests at all. That also means it doesn’t re-verify signatures or look up DNS: it reads what the receiving server recorded, and checks it against the RFCs.
# getting the headers
- New Outlook and Outlook on the web — More actions (…) › View › View message details.
- Classic Outlook for Windows — open the message, then File › Properties — the Internet headers box.
- Gmail — the ⋮ menu on the message › Show original. Paste the whole page; the summary at the top is skipped.
- Apple Mail — View › Message › Raw Source.
- Thunderbird — View › Message Source (Ctrl+U).
Use the copy in the recipient’s mailbox. A copy from Sent Items was never received over SMTP, so it carries no receiver’s results.
# what it can’t do
- Verify a signature itself — that needs the signer's public key from DNS and the exact bytes of the message as sent, and a pasted header block has neither. The receiver did verify it; this reads what it recorded, and checks the signature's own text for things no verifier would accept.
- Confirm relaxed alignment for certain — whether two names share an Organizational Domain is found by a DNS tree walk (RFC 9989 §4.10). Names under a common parent are shown as aligned if they do; the receiver's dmarc= result is the verdict.
- Vouch for anything written before your server — Received lines and Authentication-Results added upstream are claims by those systems. The page shows them, marked as such.
For what a domain publishes in DNS — the SPF record, DKIM keys, the DMARC policy — use domain --health. To build or check a DMARC record, dmarc --check. ARC (RFC 8617) is an Experimental RFC; its results are shown as receivers record them.