Email Header Analyzer

A suspicious email lands in an inbox. Is it real, or is someone impersonating your organization? Sendmarc's email header analyzer decodes the header behind any email in seconds. You can verify senders, check authentication, and trace the delivery path.

|||Open in Tools

What Is an Email Header Analyzer?

An email header is the block of metadata attached to every email. It records the sender and recipient addresses, the subject line, timestamps, and every server the message passed through on its way to the inbox.

An email header analyzer reads that metadata and converts it into a format administrators can act on. Instead of reading raw header text line by line, you get a structured breakdown: sender identity, delivery route, and authentication results for SPF, DKIM, and DMARC.

IT administrators use an email header analyzer to troubleshoot delayed delivery. Security teams use it to investigate phishing attempts. Marketing and communications teams use it to confirm outbound email infrastructure is configured correctly.

Received · Authentication-Results · DKIM-Signature
Received: from smtp.example.com (203.0.113.5)Delivery Route
by mx.corp.com with ESMTPS id a7si...
Thu, 9 May 2024 08:14:22 +0000
Authentication-Results: mx.corp.com;Auth Verdict
dmarc=pass (p=reject) header.from=example.com;
dkim=pass header.d=example.com;
spf=pass smtp.mailfrom=example.com
DKIM-Signature: v=1; a=rsa-sha256;DKIM Signature
d=example.com; s=default; c=relaxed/relaxed;
bh=P7uJWWWTGz1kSjO3Ycr9kUk...;
Subject: Suspicious login detected

Why Analyzing Email Headers Matters

Checking the header is how you confirm whether a message is actually fraudulent or understand why a legitimate email lands in Spam.

Header data also shows exactly which servers handled a message and how long each hop took. That's how a team traces a delayed or missing delivery back to its cause, rather than guessing.

Headers expose SPF, DKIM, and DMARC results in one place. That lets a team confirm messages meet the authentication standards mailbox providers and regulators require.

What Sendmarc's Email Header Analyzer Shows You

Paste or upload any email header and get a structured breakdown across four areas.

Authentication results

SPF verifies the server is authorized to send for the domain. DKIM confirms nothing altered the message in transit. DMARC ties the two together and tells receiving servers what to do when a message fails authentication checks. Sendmarc's email header analyzer parses all three, explains the result in plain language, and flags configuration gaps.

Authentication

paypal-secure-verify.ru

SPFFail
IP not in SPF record
DKIMNone
No signature present
DMARCFail (reject)
Policy: reject
Sender failed all three authentication checks - high risk of spoofing.

Delivery route

Every server that handles an email adds a timestamp to the header. The analyzer parses these in order, calculates the time spent at each hop, and flags unexpected relay servers or unusually long delays.

Email journey

3 hops • 4.0s

185.220.101.47
🇷🇺 Russia · Tor exit node
0s
relay.anonymoushost.de
🇩🇪 Frankfurt · anonymous relay
+3.1s
mx.google.com
🇺🇸 United States · Google MX
+0.9s
2 of 3 hops flagged - suspicious relay infrastructure detected.

Sender reputation

Sendmarc's email header analyzer cross-references the originating IP address against reputation data to surface abuse scores and known spam infrastructure. It checks every hop, not just the first one.

IP reputation

185.220.101.47

Country
🇷🇺 Russia
Abuse Score
87 / 100
ISP
Tor exit node
Risk
High
High abuse scoreListed on 6 blocklistsKnown phishing infrastructure

Plain-language summary

Not everyone needs to read raw authentication records. Marcy, Sendmarc's AI Analyst, reads the full result set and writes a short, jargon-free summary of what passed, what failed, and what to do next.

AI Agent Interpretation

Marcy
Marcy · AI Security Analyst

This email failed all three authentication checks. The sending IP is a known Tor exit node listed on 6 blocklists. Combined with the lookalike domain paypal-secure-verify.ru, this is a high-confidence phishing attempt - do not click any links.

Verdict: high-confidence phishing

How to Use Sendmarc's Email Header Analyzer

  1. Open the email. In your email client, locate the option to view the full header.
  2. Copy the header. Copy the full header text, or download the email as a file.
  3. Paste or upload. Paste the header into the analyzer, or upload the email file directly.
  4. Select Analyze headers. The tool processes the header and returns a result.
  5. Review the result. Check authentication status, delivery route, and sender reputation.
  6. Act on it. Confirm sender legitimacy, resolve a delivery issue, or flag the message for further investigation.

Once you know how to read email headers, spotting an inconsistency, an unexpected relay, or a failed authentication check becomes easy. Run an email header check any time a message looks suspicious, rather than guessing its legitimacy.

Email Header Analyzer FAQs

What is an email header?

An email header is the block of metadata attached to every email. It includes the sender and recipient addresses, timestamps, the servers the message passed through, and authentication results for SPF, DKIM, and DMARC.

How do I analyze an email header?

Open the email in your email client and locate the option to view the full header. Copy the header and paste it into an email header analyzer, or upload the email file directly, to see sender, routing, and authentication data.

What information can I get from an email header?

An email header shows the sender and recipient addresses, the servers the email passed through, when it was sent, and the results of SPF, DKIM, and DMARC checks.

Can email headers be spoofed?

Some header fields, including the "From" address, can be forged. DMARC detects this by verifying whether the source is authorized to send on behalf of the domain, and it tells receiving servers what to do when that check fails.

How does an email header affect delivery?

Receiving servers check header authentication results, SPF, DKIM, and DMARC, before deciding whether to deliver a message. A failed check increases the chance that a legitimate email lands in Spam or gets rejected.

Does an email header analyzer stop phishing emails from arriving?

No. An email header analyzer helps you investigate a message after it arrives. Blocking unauthenticated email before it reaches an inbox requires full DMARC enforcement.

What is the difference between SPF, DKIM, and DMARC in a header?

SPF confirms the sending server is authorized to send on behalf of the domain. DKIM confirms that nothing altered the message content in transit. DMARC uses the results of both to determine what receiving servers should do with the message, and reports the outcome back to the domain owner.

Can I check more than one email at a time with an email header analyzer?

Sendmarc's email header analyzer checks one message at a time. For ongoing, domain-wide visibility into every sender and authentication result, use a DMARC management solution to monitor traffic continuously.

One email analyzed, every sender monitored

A spot-check tells you what happened to one message. Sendmarc's DMARC reporting shows you what's happening across your entire domain - every sender, every day. Who's sending on your behalf, which senders are misconfigured, and whether anyone is impersonating you right now.

$2.9B
in BEC losses reported in 2023 - all exploiting unauthenticated email
4-6 weeks
typical time from monitoring to full enforcement
100%
visibility into every sender on your domain - including the ones you don't know about
portal.sendmarc.com/reporting
Compliance
Deliverability
Reputation
Threats
Compliance
98.5%
12,278 / 12,465
98%
Volume
12.5K
Senders
10
214 IP addresses
Passing DKIM & SPFDKIM onlySPF onlyFailures
SenderComplianceVolumeFailingPassingCategory
Microsoft Exchange Online
Mailbox provider
100%
5,925
0
5,925
Authorized
Google Workspace Forwarder
Mailbox provider
100%
306
0
306
Forwarder
North-West GSM Russia
ISP
0%
48
48
0
Suspicious