Free tool Runs in your browser

Is this email safe?

Paste a suspicious message and read it three ways at once: the SPF, DKIM and DMARC verdict, every link taken apart so a lookalike cannot hide, and the addresses, domains and hashes pulled out as indicators. All in your browser.

The headers are read in this page. Nothing is uploaded, logged or stored, which matters because headers contain addresses and internal host names.

Paste and read

The email

Where to find the headers
  • Gmail: open the message, then the three dots, then Show original.
  • Outlook (desktop): open the message in its own window, File, Properties, then copy the Internet headers box.
  • Outlook on the web: the three dots, View, View message details.
  • Apple Mail: View, Message, All Headers.
  • Thunderbird: View, Message Source.

Forwarding a message rewrites the headers, so always use the original.

What it says

How to read the result

What actually proves a sender.

SPF, DKIM and DMARC

SPF says the sending server was allowed to send for that domain. DKIM proves the message was not altered and came from the domain that signed it. DMARC ties either one back to the address you see, which is the part that matters.

The name is not the address

Mail clients show a display name. Anyone can set it to a bank, a colleague or another address entirely. This tool compares it with the real sender.

Reply-To is the payment trick

An invoice that looks right but replies to a lookalike domain is how business email compromise works. A mismatch there deserves a phone call to a known number.

A pass is not innocence

Attackers register their own domains and authenticate them properly. All-pass on a domain you have never dealt with is still a first contact, not a guarantee.

New to this? Read the phishing triage walkthrough, which uses this tool and the others in order.

Worried your own domain can be spoofed?

Check whether your SPF, DKIM and DMARC actually stop someone sending as you, or have us run a phishing simulation against your people.