d4 · tools · email headers
Where did this message really come from? Paste the raw headers of a delivered email and this reads them back for you: who it claims to be from, whether SPF, DKIM and DMARC passed, the full delivery path with the delay at each hop, and a plain-English note on anything that looks off. The companion email security checker audits a domain's published policy; this one inspects one message you have received. Everything runs in your browser; nothing you type leaves this page.
Received: lines are stamped on by each mail server in turn and prepended, so the newest hop sits at the top; they are shown here reversed into delivery order. Authentication results are only as trustworthy as the server that wrote them, normally your own inbound provider; results from servers before that point can be forged. Clock skew between servers can make a hop delay look negative or inflated, so treat the timings as indicative rather than exact.