Skip to content
Toolbench

Email Header Analyser

Read the delivery path out of raw headers — who handed the message to whom, how long each hop took, and what the checks said.

Runs entirely in your browser

Loading tool...

How to use

  1. In your mail client, open the original or raw source of the message.
  2. Copy the headers — everything above the message body — and paste them here.
  3. Read the delivery path from the top: hop 1 is where the message started.
  4. Look for a hop with a long delay; that is where a delayed message waited.

Features

  • Folded headers rejoined, so a long subject is not torn in half.
  • Received lines reversed into delivery order and numbered from the origin.
  • Time spent at each hop, and the total.
  • SPF, DKIM and DMARC results read from whichever header carries them.
  • Runs entirely in your browser — an email header is not something to upload.

Frequently asked questions

Why is the delivery path upside down in the raw message?
Because each server adds its `Received:` line at the top rather than the bottom, so the file reads newest-first. The last line in the file is the first hop the message took. They are reversed here, and numbered from the origin, which is how anyone actually wants to read them.
The message took a long time. Which hop was slow?
The one with the large delay. Each hop shows the seconds between its own timestamp and the previous server's — a queue on a receiving server, a greylisting delay or a spam scan shows up as a gap of minutes. Note that clocks are set by different organisations, so a small negative gap is a clock difference, not a time machine.
Can I trust what the headers say?
Only from the point where you trust the server. Any sender can invent `Received:` lines, so the lower ones — closest to the origin — are the least reliable. The lines added by your own provider, and the SPF and DKIM results it recorded, are the ones worth relying on.

Read a Set-Cookie header attribute by attribute, and see which protections are missing.

Everything this page can read about your browser, screen and system — shown to you instead of collected.

Break a URL into its scheme, host, path, query parameters and fragment.

What kind of hash is this? A ranked shortlist, and an honest note about when the answer cannot be known.