Email and DNS toolkit limitationsResults are public-DNS observations, local parsers and bounded cryptographic checks—not proof of identity, delivery, reputation or compliance.
Message and DMARC inputs remain in the browser, but copying, forwarding or exporting can alter evidence. DKIM RSA-SHA256 verification depends on complete unmodified source and the currently published key; unsupported algorithms are labelled. DNSSEC uses public-resolver validation plus DS digest matching, while some TLSA selectors cannot be byte-matched in this runtime. No SMTP server is required or contacted. Monitoring stops when its page closes. Live delivery, mailbox acceptance, commercial reputation, inbox-placement and proprietary blacklist coverage are excluded.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
Delivered-message evidence
Email and .eml analyser
Open a complete .eml file or paste headers to inspect the route, timing, authentication, identities and attachment names entirely in this tab.
Browser-only input: message content is never uploaded, saved, put into analytics or browser storage. It is cleared when you leave or press Clear. Maximum input: 2 MB. DNS names needed for public-key lookup are sent to the site resolver.
Warning: headers can be forged before a trusted receiving hop. Treat Authentication-Results as trustworthy only when added by a system you trust, and compare with the original message source.