ToolsCVE trackerATT&CKCIDRDNSEmail securityHeadersTrackersTLSMy connectionCSP builderEmail headersJWTCert decoderPassphrasePassword checkHash & encodesecurity.txtDNSSEC & CAA

d4 · tools · email headers

Email header analyser.

Where did this message really come from? Paste the raw headers of a delivered email and this reads them back for you: who it claims to be from, whether SPF, DKIM and DMARC passed, the full delivery path with the delay at each hop, and a plain-English note on anything that looks off. The companion email security checker audits a domain's published policy; this one inspects one message you have received. Everything runs in your browser; nothing you type leaves this page.

Received: lines are stamped on by each mail server in turn and prepended, so the newest hop sits at the top; they are shown here reversed into delivery order. Authentication results are only as trustworthy as the server that wrote them, normally your own inbound provider; results from servers before that point can be forged. Clock skew between servers can make a hop delay look negative or inflated, so treat the timings as indicative rather than exact.