How to Read and Analyze Email Headers
Every email transmitted across the Internet is wrapped in hidden metadata known as RFC 822/5322 headers. While email apps only show the basic sender, recipient, and date, the underlying raw headers document the exact physical journey of the email through various Mail Transfer Agents (MTAs).
Analyzing headers helps identify email spoofing, verify cryptographic signatures, diagnose deliverability delays, and uncover phishing origins.
| Security Standard | Primary Function | How It Validates Authenticity | Impact of Failure |
|---|---|---|---|
| SPF (Sender Policy Framework) | IP Authorization | Verifies whether the sending MTA's IP is authorized in the sender domain's DNS TXT record. | Sent to Spam or rejected (Softfail / Fail). |
| DKIM (DomainKeys Identified Mail) | Cryptographic Integrity | Validates an asymmetric public-key signature attached to the body and critical headers. | Indicates potential in-transit message tampering. |
| DMARC (Domain-based Message Authentication) | Enforcement Policy | Aligns SPF and DKIM with the visible From: address and specifies action (none, quarantine, reject). |
Direct message rejection at gateway level. |
| ARC (Authenticated Received Chain) | Mailing List Preservation | Preserves authentication results when emails pass through intermediaries or forwarding services. | Prevents legitimate forwarded mail from failing DMARC. |
How to Find Raw Headers in Popular Email Clients
Gmail / Google Workspace
Open the email > Click the three vertical dots next to Reply > Select "Show original" > Click "Copy to clipboard".
Microsoft Outlook (Desktop)
Double-click the email to open it > Go to File > Properties > Look for the "Internet headers" box at the bottom.
Proton Mail
Open the message > Click the More (three dots) menu > Select "View headers" or download the raw message file.
Apple Mail (macOS)
Select the message > Go to the top menu bar > Click View > Message > Raw Source (or press Option+Command+U).
Understanding MTA Hop Latency & Delivery Bottlenecks
Every server that handles an email appends a new Received: header at the very top of the stack. By reading these lines in reverse chronological order, our tool computes the exact time difference (in seconds) between each hop:
Healthy email deliverability usually completes each hop within 0 to 2 seconds. If a hop shows a delay of 30+ seconds, it reveals a bottleneck such as graylisting, heavy spam filtering queues, or overloaded remote MTAs.
Frequently Asked Questions
Does this tool save or log my emails?
No. Analysis runs completely in client-side JavaScript inside your browser. No headers or message content are uploaded or saved to any database.
What does "Hop Delay: +0s" mean?
A zero-second delay means the handoff between the sending and receiving mail servers occurred within the same clock second, reflecting optimal transmission speed.
Why is my DMARC status "Not Found"?
If the receiving server's authentication filter did not output an explicit dmarc=pass or dmarc=fail verdict inside the Authentication-Results header, the status shows as Not Found. You can verify whether the sending domain has an active policy using our built-in Live Domain MX Lookup tab.

