Free tool Runs in your browser
Is this email safe?
Paste a suspicious message and read it three ways at once: the SPF, DKIM and DMARC verdict, every link taken apart so a lookalike cannot hide, and the addresses, domains and hashes pulled out as indicators. All in your browser.
The headers are read in this page. Nothing is uploaded, logged or stored, which matters because headers contain addresses and internal host names.
Paste and read
The email
Where to find the headers
- Gmail: open the message, then the three dots, then Show original.
- Outlook (desktop): open the message in its own window, File, Properties, then copy the Internet headers box.
- Outlook on the web: the three dots, View, View message details.
- Apple Mail: View, Message, All Headers.
- Thunderbird: View, Message Source.
Forwarding a message rewrites the headers, so always use the original.
What it says
How to read the result
What actually proves a sender.
SPF, DKIM and DMARC
SPF says the sending server was allowed to send for that domain. DKIM proves the message was not altered and came from the domain that signed it. DMARC ties either one back to the address you see, which is the part that matters.
The name is not the address
Mail clients show a display name. Anyone can set it to a bank, a colleague or another address entirely. This tool compares it with the real sender.
Reply-To is the payment trick
An invoice that looks right but replies to a lookalike domain is how business email compromise works. A mismatch there deserves a phone call to a known number.
A pass is not innocence
Attackers register their own domains and authenticate them properly. All-pass on a domain you have never dealt with is still a first contact, not a guarantee.
New to this? Read the phishing triage walkthrough, which uses this tool and the others in order.
Worried your own domain can be spoofed?
Check whether your SPF, DKIM and DMARC actually stop someone sending as you, or have us run a phishing simulation against your people.
More free tools
- checkYourDomainSecSee what the internet already knows about your domain.
- Web response analyzerGrade security headers, evaluate CSP, and read the certificate.
- Layered decoderTake base64, hex and gzip wrapping off a payload.
- Static file analysisRead a file's format, hashes, PE internals and hidden content, all in your browser.