Email header decoder

The sender name in your mail program is whatever the sender felt like typing. The headers underneath record what really happened. Paste them here and your browser decodes them line by line.

How do I get the headers out of my mail program?
Gmail in a browser
With the message open, click the ⋮ button beside Reply and pick Show original. Copy to clipboard takes everything; Download original saves it as an .eml file.
Outlook on the web, Outlook.com and the new Outlook
With the message open, use … (More actions) → View → View message details, then select the whole text and copy it. … → Download saves the complete message as .eml.
Classic Outlook for Windows
Open the message in a separate window (double-click), then go to File → Properties. Click in the Internet headers box, press Ctrl+A, then Ctrl+C.
Apple Mail
Select the message, then View → Message → All Headers (⇧⌘H). Raw Source (⌥⌘U) shows the body too, and File → Save As… with the “Raw Message Source” format produces an .eml file.
Thunderbird
With the message open, choose More → View Source (Ctrl+U), select everything and copy. File → Save As → File writes an .eml.
Phones and tablets
Most mail apps on phones hide the headers completely. Read the message from a computer, or forward it to yourself as an attachment so the original headers travel with it.

🔒 The decoding is done by your browser. What you paste is never transmitted to our server, no link in the message is followed and no image is fetched.

One message, four sender fields

A paper letter has a name signed at the bottom, a return address on the envelope and a postmark added by the post office. Nothing forces the three to agree. Email works the same way, with one more field thrown in.

FieldSet byWhat it is for
Display nameThe sender, freelyThe only part most phones show. It can say anything, including “PayPal” or a full fake address.
From addressThe senderThe address your mail program displays, and the one DMARC protects.
Return-PathThe sending serverWhere bounces go. SPF checks this address, and it’s often on a different domain from From.
Reply-ToThe senderWhere your answer goes if you press Reply.

The “Who really sends it” block puts the four side by side and shows the registrable domain of the From address in bold. That way paypal.com.account-review.help reads as what it is, a name under account-review.help.

The verdict your own provider wrote

When a message arrives, the receiving service (Gmail, Outlook, your company’s server) tests it and writes the outcome in an Authentication-Results header at the top. This tool doesn’t redo those tests. It reads that header, because it’s the one line the sender had no way to write.

spf=pass
The connecting server is on the list published by the Return-Path domain.
dkim=pass
A cryptographic signature covers the message and it still verifies, so the content wasn’t altered. The d= value names the domain that signed.
dmarc=pass
At least one of the two passed and its domain matches the one in From.

If there are several Authentication-Results headers, only the topmost counts. The others were added earlier on the route and could have been forged. When there’s none at all, the tool falls back to the newest ARC-Authentication-Results, then to Received-SPF.

A pass proves the message comes from the domain it names. It doesn’t prove that domain is the company you have in mind. Anyone can register paypal-billing-alerts.help and configure it perfectly, and the sample message on this page passes all three checks.

The signals the decoder looks for

Signals are sorted into three levels. A single red one is enough for the overall “Strong warning signs”, and yellow gives “Be careful”.

  • Display name against address. A name that contains a different email address, or that names a brand from our list while the address sits on another domain. It’s red when that address is a free mailbox such as gmail.com.
  • Sender domain. Mixed alphabets, invisible characters, or a spelling within one or two letters of a known brand. These are the same tests the lookalike character detector runs.
  • Reply-To on a free mailbox while the message claims to come from an organization’s domain. That’s the pattern behind fake invoices and the “urgent request from the director”.
  • Failed checks. dmarc=fail is red. SPF fail or softfail and an invalid DKIM signature are yellow, because honest forwarding and mailing lists cause them too.
  • Filter marks. Microsoft’s spam confidence level (SCL) of 5 or more, a category such as PHSH or SPOOF, compauth=fail, or an X-Spam-Flag: YES.

If you paste the whole message, or drop the .eml file, the body gets parsed as well, without being displayed and without anything being loaded from it. Links are grouped by real destination domain, once Microsoft Safe Links, Proofpoint and Google redirects have been unwrapped. A link whose visible text names one site while its address leads to another is red. Attachments are judged by extension: programs and scripts, double extensions such as invoice.pdf.exe, HTML pages, Office files with macros.

Reading the route

Every server that handles a message adds a Received line above the ones already there. The decoder flips them into chronological order and shows, for each hop, which machine handed the message to which, whether the link was encrypted with TLS, and how long the hop took. Any delay over an hour is highlighted.

The “origin server” is the first public IP address on the route, and it deserves some suspicion. The earliest hops are written by the sender’s own machines, so they can be made up. The last hops, added by your provider, are the ones you can rely on. For mail sent from a webmail service, the origin is that service’s server, not the writer’s home connection.

Headers can’t tell you whether a real account was taken over. A message sent from a colleague’s hacked mailbox passes every check here. So when a message asks for money, a password or a change of bank details, confirm through a channel you already trust, such as a phone number you had before the message arrived.

Questions people ask

How do I see the full headers of an email?

In Gmail, open the message, click the three-dot menu and choose “Show original”. In Outlook on the web, it’s “…” then View › View message details. In Apple Mail, View › Message › All Headers. The box above the results on this page lists the steps for each program.

Can I find the sender’s location or IP address from the headers?

Sometimes you’ll get the IP address of the sending server, rarely that of the person. Gmail, Outlook.com and most webmail services leave the writer’s own address out. And an IP address identifies a network, not a street.

The message passed SPF, DKIM and DMARC. Is it safe?

It means the message was sent by the domain shown in the From address and wasn’t modified. Now check that this domain really is the organization’s, letter by letter. A fraudster’s own domain passes authentication as easily as anyone’s.

Why did SPF fail on a message that looks legitimate?

Usually because of forwarding. When a mailbox forwards automatically to another, the forwarding server isn’t on the original domain’s SPF list. If DKIM still passes, DMARC passes too and the message is fine.

What do SCL, BCL and compauth mean in Outlook headers?

They’re Microsoft filter results. SCL is the spam confidence level, from -1 (trusted) to 9, and 5 or above goes to Junk. BCL rates bulk senders from 0 to 9. compauth is Microsoft’s combined judgment of SPF, DKIM, DMARC and sender reputation.

Is it safe to paste a private email here?

A script in your browser processes the text, and it isn’t sent to our server. No link in the message gets opened and no image gets requested, so the sender can’t tell that you examined it.