Email Header Analyzer
Email Header Analyzer helps you parse and analyze email headers for diagnostics, for secure mail validation, policy checks, and troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
Email Header Analyzer parses the raw headers of an email message to trace its delivery path, identify authentication results (SPF, DKIM, DMARC), measure delivery delays, and detect spam indicators.

Why It Matters
- →Spam Detection: Identify forged or suspicious sender information
- →Deliverability: Diagnose why emails land in spam
- →Authentication: Verify SPF, DKIM, DMARC pass/fail results
- →Path Tracing: See exact route an email took from sender to recipient
How to Read Results
- Received headers: Read bottom-to-top (earliest server first)
- Authentication-Results: Shows SPF/DKIM/DMARC pass or fail status
- X-Spam headers: Mail server spam scoring (X-Spam-Score, X-Spam-Flag)
- Message-ID: Unique identifier for tracking a specific email
Technical Background
Email headers are defined in RFC 5322 (Internet Message Format) and RFC 7001 (Authentication-Results header). Each mail server that handles an email prepends a "Received:" header containing: from (originating host), by (receiving host), via (protocol), with (transport security), id (message identifier), and timestamp. Reading Received headers from bottom to top reconstructs the complete delivery path from sender to recipient.
The Authentication-Results header (prepended by the final receiving server) summarizes SPF, DKIM, and DMARC verification outcomes. "spf=pass" means the sending IP is authorized in the domain's SPF record. "dkim=pass" means the cryptographic signature verified correctly. "dmarc=pass" means the message is aligned with the domain's DMARC policy. DKIM-Signature headers contain the selector (s=), signing domain (d=), hashing algorithm (a=), and the base64-encoded signature (b=).
Key headers for forensic analysis: Return-Path specifies the bounce address (envelope sender, which differs from From:). X-Originating-IP may reveal the actual client IP behind webmail portals. Reply-To sets a different address for replies, commonly manipulated in phishing. Date header timezone can hint at sender location. X-Mailer or User-Agent reveals the email client or sending platform. X-Spam-Score and X-Spam-Report headers (added by SpamAssassin and similar) explain why a message was flagged.
Phishing and email fraud detection focuses on discrepancies: From: domain vs SPF/DKIM signing domain mismatch, Received chain showing unexpected geographic origins, authentication failures combined with domain lookalikes, and homograph attacks using Unicode characters in domain names. Analysts correlate Message-ID format, X-Mailer signatures, and IP geolocation to attribute emails to specific threat actors or sending infrastructure.
In corporate security incident response, email header analysis is used to investigate phishing attacks, business email compromise (BEC), and account takeover attempts. Security teams extract indicators of compromise (IOCs) from headers: sending IP ranges, mail server fingerprints, unusual routing paths, and authentication failures. These IOCs are fed into SIEM systems and threat intelligence platforms. Automated email security gateways (SEGs) like Proofpoint, Mimecast, and Microsoft Defender for Office 365 use header analysis at scale to block threats before delivery. Manual header analysis remains an important skill for security analysts investigating emails that bypass automated filters.
Common Errors and How to Fix Them
- ProblemThe headers pasted are those of a message you forwarded to yourself, so the analysis shows your own server instead of the original sender.
- FixForwarding creates a new message. Open the original in the mailbox where it arrived and use 'Show original' (Gmail), 'View message source' (Outlook on the web) or View > Message > All Headers (Apple Mail), then copy everything above the body.
- ProblemThe Received headers are read top to bottom and the first line is mistaken for the sender's server.
- FixEach server prepends its Received line, so the bottom one is the oldest and the top one is the final delivery. Start at the top and walk down to the first header added by a server you trust; lines below that point can be forged by the sender.
- ProblemAn Authentication-Results header showing spf=pass and dkim=pass is trusted, although it was added by an unknown server earlier in the path.
- FixOnly trust Authentication-Results whose authserv-id matches your own receiving system (RFC 8601). A sender can insert fake results; well-behaved receivers strip or ignore foreign ones.
- ProblemDelivery delays are calculated by subtracting Received timestamps without accounting for time zones.
- FixEach timestamp carries its own offset (-0300, +0000). Convert all of them to UTC before comparing, and remember that a misconfigured clock on one server can produce negative or inflated delays.
- ProblemA message from a mailing list shows dkim=fail and dmarc=fail, and it is labelled a spoof.
- FixLists often modify the subject or append footers, breaking the original signature. Look for ARC-Authentication-Results (RFC 8617) with i=1, which records the authentication results as the list first received them.
- ProblemSPF passes but DMARC still fails, which seems contradictory.
- FixCheck smtp.mailfrom in Authentication-Results: SPF probably passed for the email service's bounce domain, not for the From domain. Configure a custom return-path or aligned DKIM signing with that provider.
Frequently Asked Questions
How do I get the full headers of an email?
In Gmail, open the message, click the three-dot menu and choose 'Show original'. In Outlook on the web, use the three-dot menu, then View and 'View message source'; in desktop Outlook, open File > Properties and copy the Internet headers box. In Apple Mail, choose View > Message > All Headers. Copy everything down to the first blank line.
Which Received header shows the sender's real IP address?
Start from the top, which is your own provider's final hop, and move down until you reach the line where your provider's boundary server records a connection 'from' an external host. The IP in that entry is the last one your side can vouch for. Lines below it were written by servers you do not control and may be invented.
What is ARC and why does it appear in my headers?
Authenticated Received Chain (RFC 8617) lets intermediaries such as mailing lists and forwarding services record the SPF, DKIM and DMARC results they saw and seal them with their own signature. Each intermediary adds an ARC-Authentication-Results, ARC-Message-Signature and ARC-Seal set with an instance number i=. The final receiver can then trust the original results even if the message was modified.
Is it safe to paste email headers into an online tool?
Headers do not contain the message body, but they reveal email addresses, internal hostnames, IP addresses and sometimes client software versions. Remove anything you consider sensitive, for example by replacing internal hostnames, before pasting. The authentication results, timestamps and public relay IPs are what matter for diagnosis.
What does the X-Spam-Score value mean?
It is the score assigned by the receiving server's content filter, often SpamAssassin or a similar engine, where higher means more suspicious. In SpamAssassin's default setup, 5.0 is the threshold for marking spam. This tool warns above 2 and flags above 5, but scales vary between filters, so check the accompanying rule names to see what triggered points.
Academic Documentation
Protocol context and primary references
DMARC.org
Domain-based Message Authentication standard
Open source →
SPF Project
Sender Policy Framework documentation
Open source →
IETF
Internet Engineering Task Force
Open source →
RFC Editor
Official RFC documentation
Open source →
IANA
Internet Assigned Numbers Authority
Open source →
M3AAWG
Operational guidance for email authentication and abuse handling.
Open source →
REST API Documentation
v1.0GET /api/tools/email-header
curl -X POST https://epcybertools.com/api/tools/email-header \
-H "Content-Type: application/json" \
-d '{"headers":"Received: from mail.example.com\nDate: Mon, 1 Jan 2024 12:00:00 +0000\nFrom: [email protected]\nTo: [email protected]\nSubject: Test Email"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# View raw email headers in Apple Mail
# View > Message > All Headers (Shift+Cmd+H)
# Fetch email headers via curl (IMAP)
curl -s --url "imap://mail.example.com/INBOX" -u user:pass --request "FETCH 1 RFC822.HEADER"
# Show MTA delivery path
grep "Received:" email.eml | tac