> safe mail-header
Read a mail header
An email feels wrong? The header lines reveal more than the sender name: who really sent it, whether the sending domain allowed that, and what route the email took. Paste them here, everything stays in your browser.
Paste here (Ctrl+V, Cmd+V on a Mac). The whole email works too: only the part before the first blank line is read.
Try it out
What stands out
The key details
Did the sending domain allow the email?
The receiving mail server entered these results. This reader does not recalculate them.
Route of the email
The first stop is the sender, the last one your mailbox. It is read from the Received lines.
More on this topic: Spot a scam (questionnaire) · Check a link
The header lines never leave this device. They are not stored and not looked up.
How it works
- 01Open the suspicious email, but tap nothing in it. Look in the email’s menu for “Show original”, “View source” or “Internet headers”. In Gmail it is “Show original” (three dots on the message), in Outlook for Windows it is under “File, Properties, Internet headers”, in Thunderbird Ctrl+U opens the source, in Apple Mail “View, Message, All Headers” or “Raw Source” shows the header. Menus change; for other providers, search for “show email headers” plus the program name.
- 02Copy the text and paste it here. It is read at once.
- 03You see the real sender, whether SPF, DKIM and DMARC passed, where replies go and over which servers the email travelled, with times. What stands out is listed below, ordered by weight.
What SPF, DKIM and DMARC are: SPF says which servers may send for a domain. DKIM is a signature showing that the email was not changed on the way. DMARC sets what happens when neither fits the sending domain. “Passed” only means the email really came from the named domain. Scammers have domains of their own with correct setup as well.
Personal data: Header lines can contain your email address, your IP address and the names of your servers. Pass them on only to people you trust, and do not post them in forums.
Limits: The reader does not check signatures itself, because it would need the whole email and a lookup online. If the results for SPF, DKIM and DMARC are missing, your provider did not enter them or you copied only part of the header. Forwarding and mailing lists change headers and can trigger notes although the email is genuine. An email with nothing unusual can still be a scam. It does not replace advice from your mail provider, your bank or the police.