Is it safe?

> safe mail-header

Read a mail header

An email feels wrong? The header lines reveal more than the sender name: who really sent it, whether the sending domain allowed that, and what route the email took. Paste them here, everything stays in your browser.

A hint, not proofThe reader only reads what the mail server wrote into the header lines and does not check any signature itself. Header lines can partly be forged. If it finds nothing, the email is not automatically genuine.

Paste here (Ctrl+V, Cmd+V on a Mac). The whole email works too: only the part before the first blank line is read.

Try it out

Nothing pasted yetAs soon as you paste header lines, the result appears here, after a short pause in typing.

More on this topic: Spot a scam (questionnaire) · Check a link

The header lines never leave this device. They are not stored and not looked up.

How it works
  1. 01Open the suspicious email, but tap nothing in it. Look in the email’s menu for “Show original”, “View source” or “Internet headers”. In Gmail it is “Show original” (three dots on the message), in Outlook for Windows it is under “File, Properties, Internet headers”, in Thunderbird Ctrl+U opens the source, in Apple Mail “View, Message, All Headers” or “Raw Source” shows the header. Menus change; for other providers, search for “show email headers” plus the program name.
  2. 02Copy the text and paste it here. It is read at once.
  3. 03You see the real sender, whether SPF, DKIM and DMARC passed, where replies go and over which servers the email travelled, with times. What stands out is listed below, ordered by weight.

What SPF, DKIM and DMARC are: SPF says which servers may send for a domain. DKIM is a signature showing that the email was not changed on the way. DMARC sets what happens when neither fits the sending domain. “Passed” only means the email really came from the named domain. Scammers have domains of their own with correct setup as well.

Personal data: Header lines can contain your email address, your IP address and the names of your servers. Pass them on only to people you trust, and do not post them in forums.

Limits: The reader does not check signatures itself, because it would need the whole email and a lookup online. If the results for SPF, DKIM and DMARC are missing, your provider did not enter them or you copied only part of the header. Forwarding and mailing lists change headers and can trigger notes although the email is genuine. An email with nothing unusual can still be a scam. It does not replace advice from your mail provider, your bank or the police.