The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Email header analysis examines the metadata added to a message as it is created, transmitted, authenticated, filtered, and delivered. It can reveal the visible sender, envelope sender, delivery route, timestamps, authentication results, message identifiers, and filtering decisions.
It is useful for investigating phishing, diagnosing delivery delays, checking SPF, DKIM, and DMARC configuration, and preserving evidence during an incident. But a header is evidence—not a complete safety verdict. A message can pass authentication because it came from a legitimate but compromised account, while a legitimate forwarded message can fail SPF.
What is an email header?
An email broadly consists of structured headers and a message body. Headers are fields such as From:, Subject:, and Received:. Some are defined by Internet standards, while others are added by Gmail, Microsoft 365, security gateways, mailing lists, and applications. The current standardized and provisional field registry is maintained by IANA.
The visible sender is only one part of the message identity:
#1 Best Overall
From:: The author or sender address shown to the recipient. It can be spoofed unless authentication verifies and aligns it.- Envelope sender: The SMTP reverse-path used for transport and bounces. After delivery, it is often represented by
Return-Path:. Reply-To:: The address used when a recipient replies. It can legitimately differ fromFrom:, but an unrelated reply address is a common phishing clue.Received:: Trace fields added by receiving mail servers as the message moves between systems.- Authentication evidence: Fields such as
Authentication-Results:,DKIM-Signature:,Received-SPF:, andARC-*. - Diagnostic extensions: Provider-specific fields, often beginning with
X-, that describe spam scoring, filtering, routing, or originating systems.
RFC 5322 defines Internet message format, while RFC 5321 describes SMTP transport and envelope concepts. These distinctions matter: From, Return-Path, and Reply-To are not interchangeable.
A shortened example
From: "Accounts Team" <[email protected]>
Reply-To: [email protected]
Return-Path: <[email protected]>
Received: from mx.example.net ...
Authentication-Results: receiver.test;
spf=pass smtp.mailfrom=mailer.example.net;
dkim=pass header.d=example.com;
dmarc=pass header.from=example.com
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; ...
Message-ID: <[email protected]>
This sample contains several identities. The visible sender is example.com, the bounce address is on mailer.example.net, and replies go elsewhere. That may be normal for a marketing platform—or suspicious. Context and alignment determine its significance.
Why analyze email headers?
Investigating suspicious messages
Headers can expose a mismatch between the claimed sender and authenticated domains, an unexpected reply address, unfamiliar sending infrastructure, inconsistent routing, or authentication failures. They may also show that a message was processed by a mailing list, forwarding service, or security gateway.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Headers rarely identify an attacker’s physical location or device. An IP address may belong to a cloud provider, VPN, shared mail system, relay, or privacy service. Treat it as infrastructure evidence, not proof of attribution.
Diagnosing delivery delays
The Received chain can reveal long gaps between hops, repeated retries, routing loops, and unexpected gateways. Google’s Messageheader diagnostic tool specifically helps identify server hops, delays, and routing problems.
Checking authentication and deliverability
Headers show whether the receiving provider recorded SPF, DKIM, and DMARC results. The important question is not only whether each mechanism passed, but whether the authenticated domain aligns with the visible From: domain.
Preserving incident-response evidence
Save the original message or .eml file, record when and where you obtained it, and avoid forwarding the suspicious message. Forwarding can alter headers and change authentication evidence. Preserve the original before extracting or sharing any text.
How to get the full email header
Use the complete original header—not a screenshot, shortened summary, or only the fields displayed beside the sender.
Rank #2
- PCI ISA Interface: This PC diagnostic card adopts standard PCI and ISA interface, easy access to desktop PC.
- 4 Digit Display: This PC mother board adopts 4 digit display, the first 2 digits indicate the current error code, and the last 2 digits indicate the previous error code.
- Strong Compatibility: This PC diagnostic 4 digit card is compatible with ny kind motherboards with the PCI and ISA bus slot. Suitable for all computers with PCI or ISA interface.
- Dual POST Code Display: This motherboard diagnostic card possesses self checking remote display function and dual POST code display, easy to view the POST code.
- High Reliability: The POST code display is composed of a dual dot matrixs hexadecimal read out that displays Power On Self Test (POST) status codes.
Gmail on the web
- Open the message.
- Select the three-dot More menu.
- Choose Show original.
- Copy the complete header or download the original message.
Gmail’s official guidance explains how to inspect authentication results and locate the Authentication-Results field. Labels can vary by account and interface.
Google Workspace
Administrators can paste the full header into Google Admin Toolbox and choose the Messageheader tool to inspect routing and delays.
Outlook and Microsoft 365
The path varies between classic Outlook, new Outlook, Outlook on the web, mobile clients, and tenant security products. Look for View source, View message details, or Internet headers. Microsoft’s documentation on message headers and authentication troubleshooting explains how to interpret Microsoft-specific fields.
Recommended Free Tools
Apple Mail and other clients
The control may be called Raw Source, Message Source, All Headers, or View Headers. If the app exposes only abbreviated headers, use the mailbox web interface or export the message as an .eml file.
How to read an email header step by step
- Save the original. Prefer an
.emldownload or the provider’s original-message function. - Do not click links or open attachments. Header analysis does not make the message safe.
- Copy every field. Do not omit the lower
Receivedlines. - Normalize folding. A continuation line beginning with whitespace belongs to the preceding field.
- Start with the newest receiving hop. The top
Receivedentry is normally the latest receiving server. - Convert timestamps to UTC. Account for time-zone offsets before comparing them.
- Check visible identity. Inspect the full
Fromaddress, display name, andReply-To. - Check transport identity. Compare
Return-Path,smtp.mailfrom,header.from, and DKIM’sd=domain. - Read
Authentication-Results. Record SPF, DKIM, DMARC, and ARC outcomes from the receiving provider. - Check alignment. A pass for an unrelated domain is not the same as an aligned pass.
- Inspect signatures and ARC. Review
DKIM-Signature,ARC-Authentication-Results, andARC-Seal. - Compare route and timeline. Look for unexpected infrastructure, gaps, retries, and contradictions.
- Correlate externally. Use mail-server logs, message trace, DMARC reports, endpoint telemetry, and the body’s links or attachments.
- Document uncertainty. Separate observed facts from conclusions.
Reading Received headers correctly
Each receiving server generally adds its own Received: line. New entries appear at the top, so the route is usually reconstructed from the bottom upward. However, “bottom to top” is not a guarantee that the bottom line identifies the attacker or original device.
A receiving server can attest only to what it observed from the immediately preceding connection. Earlier lines may have been inserted or altered by an untrusted sender. The earliest trustworthy hop depends on your trust boundary and the systems that handled the message.
Internal hops can include private hostnames, IPv6 addresses, queue IDs, TLS information, and internal timestamps. A delay is inferred by comparing adjacent timestamps, but inaccurate clocks, queueing, retries, and differing timestamp interpretations can make the result uncertain. Confirm important timing questions in provider logs.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhat the major fields mean
| Header | What it tells you | Limitation |
|---|---|---|
From |
Visible author or sender identity | Can be spoofed unless authenticated and aligned |
To, Cc |
Visible recipients | May omit BCC recipients |
Date |
Sender-generated message date | Sender clock may be wrong or manipulated |
Subject |
Message subject | Not evidence of authenticity |
Reply-To |
Reply destination | May legitimately differ from From |
Return-Path |
Envelope bounce address after delivery | May differ from From or be rewritten |
Received |
Server-to-server delivery trace | Earlier entries may be untrusted |
Authentication-Results |
Receiver’s SPF, DKIM, DMARC, ARC, and related results | Applies to that receiver and message state |
DKIM-Signature |
Cryptographic signature and signing domain | Does not prove the human sender or intent |
Message-ID |
Message identifier for correlation | Can be forged or rewritten |
In-Reply-To, References |
Threading relationships | Can be forged or rewritten |
ARC-* |
Authentication chain through intermediaries | Trust depends on trusted ARC sealers |
Content-Type, MIME-Version |
Body format and multipart structure | Useful for parsing, not sender verification |
X-Spam-* |
Provider or gateway filtering signals | Vendor-specific |
X-Originating-IP |
Sometimes a client IP | Not standardized and often absent or rewritten |
See MxToolbox’s email-header field guide for additional explanations.
Rank #3
- Essential Motherboard Diagnostic Tool: Quickly identify CPU, DRAM, VGA, and hard disk faults via colored LED indicator lights. This LPC debug card provides comprehensive system analysis for efficient computer assembly troubleshooting.
- Real-Time Hardware Analyzer with Visual Prompts: Visualize clock signals through flashing decimal points and check PCIe reset status via clear digital tube indicators. This PCIE diagnostic card displays standby power for in-depth debugging.
- Precise Fault Isolation for Technicians: for isolating issues in memory modules, graphics cards, and storage interfaces. Ideal for hardware engineers and enthusiasts performing precise motherboard diagnosis or server maintenance.
- Compact Design for Easy PC Maintenance: Built on a durable PCB, this post code analyzer is designed for straightforward use. It simplifies complex debugging tasks through real-time visual prompts and dedicated error code display.
- Specifications & Package Contents: Type: Motherboard Diagnostic Card. Material: PCB. Supports PCI & selected GIGABYTE PCIE motherboards. Package includes the diagnostic card and a user manual.
SPF, DKIM, DMARC, and ARC explained
SPF
SPF checks whether the connecting server is authorized to send for the SMTP envelope sender domain. It authenticates the envelope identity—not necessarily the visible From: address.
Therefore, SPF can pass while the visible sender is unrelated. Forwarding also commonly causes SPF failure because the forwarder’s server is not listed in the original policy. Excessive DNS lookups can create SPF evaluation problems. An SPF pass alone does not establish trust.
DKIM
DKIM uses a cryptographic signature and a public DNS key. Important tags include:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →d=: signing domains=: selector used to find the public keya=: signing algorithmh=: signed header fieldsbh=: body hashb=: signature value
A valid signature supports the integrity of signed content and control of the signing domain’s key, subject to canonicalization and signed-field rules. It does not prove that the sender is the organization the recipient expects.
DMARC and alignment
DMARC evaluates whether SPF or DKIM authenticates and aligns with the visible From: domain. A message may show spf=pass and dkim=pass yet fail DMARC if neither authenticated domain aligns with header.from. Microsoft identifies domain misalignment as a common DMARC failure.
ARC
ARC, or Authenticated Received Chain, preserves authentication results through forwarding and intermediary handling. It is especially relevant to mailing lists, forwarding services, and secure email gateways.
ARC does not make a failed message automatically legitimate. A receiver decides which ARC sealers to trust. Gmail documents cases in which ARC affects treatment of forwarded authentication results.
Common result combinations
| SPF | DKIM | DMARC | Likely interpretation |
|---|---|---|---|
| Pass | Pass | Pass | Authentication is consistent, but assess account compromise, content, links, and context. |
| Pass | Pass | Fail | Inspect header.from, smtp.mailfrom, and header.d for alignment. |
| Pass | Fail | Pass | Aligned SPF may be sufficient for DMARC; investigate broken DKIM separately. |
| Fail | Pass | Pass | Often seen when forwarding breaks SPF but aligned DKIM survives. |
| Fail | Fail | Fail | High-priority configuration or trust problem; investigate source and policy. |
| None | None | None | No useful authentication evidence; not proof of fraud by itself. |
arc=pass |
Varies | Varies | Could indicate forwarding or intermediary handling; inspect the complete ARC chain. |
Six best email header analyzers
These are recommendations by use case, not results from a controlled performance test. A parser explains a particular message; it is not automatically a DMARC-management, inbox-placement, or forensic platform.
Rank #4
- Automatic recognition analyser supporting both Type-C and 8-Pin interfaces.
- HD screen displays real-time voltage, current, D+, D-, CC1 and CC2 pin readings.
- Built-in rechargeable battery for portable use without external power supply.
- One-key retest function for quick re-diagnosis after completing a repair.
- Package contains 1 x QianLi iBridge A3 Port Tester.
1. Google Admin Toolbox Messageheader — best free general-purpose option
Best for: Gmail and Google Workspace users investigating routing and delivery delays.
The Google Admin Toolbox Messageheader tool accepts a full SMTP header, identifies server hops and delays, and helps diagnose routing issues. Its main strengths are first-party Google context and a simple workflow with no identified paid requirement for the Messageheader function.
It remains primarily a routing and parsing diagnostic tool. It does not replace phishing investigation, DNS auditing, SIEM correlation, or continuous DMARC reporting.
2. MxToolbox Email Header Analyzer — best for readable deliverability diagnostics
Best for: Marketers, administrators, and users who want a visual explanation of hops, delays, authentication, and alignment.
MxToolbox Email Header Analyzer displays relay information, possible delays, SPF and DKIM authentication and alignment, DMARC compliance, and the original header alongside the parsed result.
It is useful for deliverability-oriented diagnosis, but a free parser is not continuous monitoring. Uploading a header creates a privacy consideration. MxToolbox’s broader paid Delivery Center products are intended for ongoing monitoring and multiple operational needs, not merely decoding one message. Prices and packaging can change; the vendor page showed, on August 16, 2026, plans including $0/month, $129/month, and $399/month offerings, which should be rechecked before purchase.
3. Microsoft Message Header Analyzer — best for Microsoft 365 environments
Best for: Microsoft 365 administrators investigating Exchange Online authentication and delivery.
Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft’s header documentation explains SPF, DKIM, DMARC, composite authentication, ARC, and Microsoft anti-spam fields. It fits naturally alongside Defender for Office 365, message trace, audit logs, and tenant investigation tools.
Best Value
- 【Broad Compatibility】 - Designed with versatility in mind, our Laptop Diagnostic Card is compatible with a wide of popular motherboards. This means that whether you are dealing with older or the latest releases, the Diagnostic Debug Card ensures seamless integration. Its applicability makes it a valuable asset for both professional IT technicians and DIY enthusiasts who need performance across various systems.. monitoring.. compatible. is. with. A. and. it. function. signal. is. key. to. and. p
- Tablet PCI Motherboard Analyzer Diagnostic Tester Post Test Card for PC Laptop D. 【User-Friendly Interface】 - The intuitive three- menu system simplifies , allowing even novice users to navigate through diagnostic codes with ease. This accessibility is when time is of the during troubleshooting sessions. The quick reference the Diagnostic Debug Card offers empowers users to diagnose issues, enhancing productivity and minimizing downtime.
- Tablet PCI Motherboard Analyzer Diagnostic Tester Post Test Card for PC Laptop D. 【User-Friendly Interface】 - The intuitive three- menu system simplifies , allowing even novice users to navigate through diagnostic codes with ease. This accessibility is when time is of the during troubleshooting sessions. The quick reference the Diagnostic Debug Card offers empowers users to diagnose issues, enhancing productivity and minimizing downtime.
- 【Advanced Technology】 - The Diagnostic Debug Card is an essential tool for any technician, offering an upgraded chip solution that enhances performance and reliability. With its three- menu , users can easily navigate through hundreds of diagnostic codes, making troubleshooting tasks more efficient. This cutting- diagnostic card not only monitors voltage in real-time but also provides key monitoring functions, streamlining the repair process for laptops, desktops, and servers alike.. Diagnostic
- Tablet PCI Motherboard Analyzer Diagnostic Tester Post Test Card for PC Laptop D. 【User-Friendly Interface】 - The intuitive three- menu system simplifies , allowing even novice users to navigate through diagnostic codes with ease. This accessibility is when time is of the during troubleshooting sessions. The quick reference the Diagnostic Debug Card offers empowers users to diagnose issues, enhancing productivity and minimizing downtime.
Availability and interface depend on the Microsoft 365 edition, role, tenant, and product surface. Licensing depends on the relevant Microsoft 365 or Defender plan; the documentation does not establish a standalone public analyzer price.
4. Gmail Show original — best for no-upload inspection
Best for: Privacy-conscious Gmail users.
Gmail’s built-in Show original view displays the raw header and authentication details without requiring the message to be pasted into a public analyzer. It is the safest first step for inspecting a sensitive message in context, although it provides less visualization than a dedicated parser.
5. Outlook and Microsoft 365 built-in message details — best built-in option for Outlook users
Best for: Users who need to inspect a message without sending it to a public service.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteDepending on the client, Outlook may expose View message details, View source, or Internet headers. The built-in view supplies the evidence needed for manual analysis or local parsing and is appropriate for sensitive corporate messages.
Menu names and availability vary among new Outlook, classic Outlook, Outlook on the web, mobile, Exchange Online, and Microsoft security products. It is not itself a complete route or authentication explanation.
6. Command-line and local parsers — best for privacy, automation, and expert workflows
Best for: Security teams, developers, forensic analysts, and organizations that cannot upload headers.
Local workflows can parse an .eml file, query DNS, and correlate values with mail-server, Google Workspace, Microsoft 365, or SIEM logs. For quick inspection:
grep -iE '^(from|reply-to|return-path|received|authentication-results|received-spf|dkim-signature|arc-|message-id):' message.eml
dig TXT example.com
dig TXT selector._domainkey.example.com
dig TXT _dmarc.example.com
These commands extract or query evidence; they do not validate the specific message by themselves. A DNS record does not prove that this message passed authentication. Local parsing is powerful and private, but requires technical knowledge and careful interpretation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Email header analyzer comparison
| Tool | Best for | Upload required? | Routing | SPF/DKIM/DMARC | ARC | Automation | Privacy note |
|---|---|---|---|---|---|---|---|
| Google Admin Toolbox | Google Workspace delivery troubleshooting | Yes, to Google’s tool | Strong for hops and delays | Visible where present | Raw/header-dependent | Limited | Consider data sensitivity |
| MxToolbox | Readable deliverability diagnostics | Yes for public parser | Strong | Strong presentation | Header-dependent | Broader paid products may add it | Review retention and privacy terms |
| Microsoft tools | Microsoft 365 environments | Usually inside provider workflow | Use with message trace | Strong Microsoft context | Supported in documentation | Tenant-dependent | Enterprise controls depend on plan |
| Gmail Show original | No-upload Gmail inspection | No external upload | Manual | Authentication details shown | Raw/header-dependent | No | Best initial privacy route for Gmail |
| Outlook message details | No-upload Outlook inspection | No public upload required | Manual | Raw/header-dependent | Raw/header-dependent | No | Depends on client and tenant controls |
| Local parser and CLI | Privacy, automation, forensics | No | Custom | Custom | Custom | Strong | Data stays under your control |
How to spot phishing from headers
Stronger red flags
- The visible
Fromdomain differs from the organization being impersonated. Reply-Topoints to an unrelated domain or consumer mailbox without a plausible explanation.- Authentication passes only for a domain unrelated to the claimed sender.
- The earliest trustworthy hop conflicts with the claimed organization or expected service.
- An unexpected third-party sender appears with no business explanation.
- The message requests credentials, payment, MFA codes, or an urgent action inconsistent with normal behavior.
- Links, attachments, and the message’s requested action conflict with the sender’s usual process.
Not automatically malicious
Return-Pathdiffers fromFrom.- SPF fails after forwarding.
- The route includes Google, Microsoft, Amazon, Mailgun, SendGrid, or another delivery provider.
- The
Message-IDdomain differs from the visible sender. - Private IP addresses or provider-specific
X-headers appear. - Authentication passes but the message still looks suspicious.
Display names are especially weak evidence: “Bank Support” may hide an unrelated address. Also inspect IDN and punycode domains, which can visually resemble legitimate brands. A fully authenticated message can still come from a compromised account or malicious authorized application.
Common edge cases and mistakes
- Forged lower
Receivedlines: Earlier lines can be inserted before the first trusted receiving server. Do not assume the lowest line identifies the attacker. - Forwarding: SPF often fails at the forwarder, while DKIM survives and ARC may preserve prior authentication context.
- Mailing lists: Subject or body changes can break DKIM. ARC and list-specific handling may explain mixed results.
- Third-party senders: CRM, help-desk, marketing, and transactional services can be legitimate, but should be configured for proper authentication and alignment.
- Shared infrastructure: An IP may belong to a major provider and many unrelated customers. IP ownership alone is weak evidence.
- Timestamps: Apparent delays may reflect clock skew, retries, or queueing. Confirm important timings with logs.
- Malformed headers: Truncation, invalid folding, duplicate fields, or encoding problems can make analyzers disagree. Compare the parser with the original.
- Privacy: Headers can contain addresses, internal hostnames, IPs, tracking IDs, tenant identifiers, and unique message IDs. Redact unnecessary data or use a local tool.
- Overtrusting green badges: A summary result can hide domain alignment, forwarding, compromise, and content risks.
Which analyzer should you choose?
- One suspicious Gmail message: Start with Gmail Show original, then use Google Admin Toolbox if routing visualization helps.
- One suspicious Outlook message: Use message details or source first, then Microsoft documentation and local analysis.
- Marketing deliverability troubleshooting: MxToolbox is suited to readable hop and authentication diagnostics.
- Sensitive corporate investigation: Use provider tools, local parsing, server logs, and SIEM correlation rather than a public upload site.
- Recurring authentication problems: Choose a DMARC reporting and deliverability-monitoring platform, not merely a header parser.
- Large-scale incident response: Combine header parsing with message trace, endpoint telemetry, mailbox evidence, and provider logs.
Compare tools on privacy, authentication depth, routing analysis, provider fit, ease of use, automation, operational scale, evidence retention, enterprise controls, and cost. A free one-off parser may be exactly right for a single message but inadequate for multi-domain governance or continuous monitoring.
What to do after analysis
- Report suspicious mail through your provider or organization’s security process.
- Quarantine or block the message where appropriate.
- Reset credentials only when credential exposure is plausible, and review MFA and sign-in activity.
- Review mailbox rules, forwarding settings, audit logs, and endpoint telemetry if compromise is suspected.
- Contact the alleged sender through an independently verified phone number or website—not by replying.
- Preserve the original
.emland document observed facts separately from inferences. - If the message is yours, correct SPF, DKIM, DMARC, sending-source, and alignment configuration, then verify with provider logs and DMARC reports.
For standards reference, consult RFC 5321, RFC 5322, RFC 6376, RFC 7208, RFC 7489, and RFC 8617.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

