Tools / Header Analyser
Is this email really from who it says?
Every email carries a record of where it came from and what your mail server checked on the way in. Paste that record here and get a plain-English reading: whether the sender is verified, whether the identities line up, what the sending server and domain are known for, and where the links go.
SPF · DKIM · DMARC · Alignment · Sender reputation · Domain age · LinksFree · Nothing stored · PDF report
What it checks
What the receiver verified
The Authentication-Results your own mail server wrote: SPF (was the server allowed to send for the envelope domain), DKIM (does the signature verify, and for which domain), DMARC (did anything aligned with the From pass), ARC for forwarded mail.
Who it claims to be from
The visible From against the Return-Path, the DKIM signing domain and any Reply-To. A Reply-To at a webmail domain, a display name that is really an address, or a brand name on an unrelated domain are the shapes of invoice fraud and account phishing.
The sending domain
Age and registrar over RDAP, the URLhaus and ThreatFox host lists, punycode and lookalike patterns (a digit for a letter, a brand inside a domain the brand does not own), and whether it can receive a reply at all.
The route it took
Every Received: hop, oldest first, with the delays between them; the first external server identified and checked against the threat feeds, mail blocklists and its network's record; HELO against reverse DNS.
Links, attachments and wording
Paste the whole message source and every link is listed: shorteners, bare IP addresses, punycode, lookalike hosts, downloads, and which ones leave the sender's domain. Attachment types that carry malware are named. Pressure wording in the subject is noted.
A verdict, not a score
Likely legitimate, suspicious, or very likely phishing, with the two or three signals that decided it, what to do next, and a PDF to send to whoever needs convincing.
How to get the headers
In Gmail, open the message, click the three dots at the top right and choose Show original, then Copy to clipboard. In Outlook on the desktop, open the message in its own window and go to File, Properties: the Internet headers box at the bottom is what you want. In the new Outlook and Outlook on the web, use the three dots, View, View message source. In Apple Mail, View, Message, All Headers, then select and copy. On a phone it is usually easier to forward the message as an attachment to yourself and open it on a computer.
Paste the headers alone to check authentication and the route; paste the whole source (which is what Show original and View message source give you) to have the links and attachment names read as well. Nothing you paste is written anywhere: it is held in memory for half an hour so the PDF can be produced, and discarded.
One caution the tool cannot remove: a message that authenticates perfectly can still be sent from a compromised account. Authentication tells you the message came from the domain it claims; it does not tell you the person meant to send it. Requests to change bank details, buy gift cards or bypass a process deserve a phone call however good the headers look.
Also in Tools