Email Header Check
Paste the raw source of a suspicious email and this tool inspects its headers locally for spoofing and phishing tells: SPF/DKIM/DMARC results, From vs Reply-To vs Return-Path mismatches, display-name impersonation, the routing path, and every link (shown defanged so it is safe to look at). Built for the input to be hostile.
Read the Email Header Check guide for how to get the raw source and read the results.
Nothing is uploaded. The email is parsed in this browser tab and discarded when you reload. It is safe to paste a suspicious email here. The message body is never rendered, and every link and address is defanged and shown as inert text. View source to confirm there are no network calls.
Paste the email source
Parsed: locally, in this browser tab
All analysis is plain string parsing in your browser. No DNS lookups, no uploads, no tracking.
Analysis complete