Tool guide limitationsGuides explain the intended workflow but cannot cover every device, provider or operating condition.
Interfaces and external services can change. Follow the current on-screen controls, check dates and vendor documentation, and verify important results independently before acting on them.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
DNS and email
Email Header Analyser guide
Inspect local message headers for relay order, delays, authentication and spoofing indicators.
Open Email Header AnalyserWhat you need
- Complete raw email headers or an EML file
How to use it
- 1Obtain the original message source.
- 2Paste or select it without editing.
- 3Run the analysis.
- 4Review authentication, identity warnings and the relay timeline.
Understanding the results
- Read Received headers chronologically and compare From, Return-Path and authentication domains.
Recommended next actions
- Compare suspicious findings with the recipient provider's message trace.
Common problems
- Forwarding, mailing lists and copied partial headers can change or remove evidence.
Privacy and security
- Header content remains in the browser but may contain addresses, IPs and identifiers.
Worked example
- Scenario
- Investigating a suspicious invoice email
- Example input
- Original unmodified message headers
- How to read it
- A From-domain mismatch plus failed DMARC highlights risk, while the relay timeline shows where trusted evidence begins.
Limitations
- Headers can be forged before the first trusted relay and do not prove sender identity alone.
Do not rely on one result for a production, security, safety, purchasing or contractual decision. Verify important findings independently.