Phishing email analyzer
Paste a raw email. This page reads the headers the way a mail server does and tells you, in plain English, what SPF, DKIM and DMARC each concluded — and what none of them prove. Nothing you paste is uploaded.
What this tool does
Paste a raw email — just the headers, or the headers and the body — and this page reads it the way a mail server does, then explains the result in plain English. It is built for the person who has been told to “check the headers” and has never been shown what they mean.
The three authentication checks
Most mail now arrives carrying the verdict of three checks, written into an
Authentication-Results header by the server that received it.
SPF asks whether the sending server was on the list of machines allowed to
send for the envelope sender's domain. DKIM verifies a cryptographic
signature, proving the signed parts of the message were not changed after signing.
DMARC is the one that matters most to a reader: it asks whether the domain
in the From line you actually see lines up with whatever SPF or DKIM authenticated.
The tool reports what each one concluded and, more importantly, what it does not prove. All three can pass on a message that is pure phishing, because an attacker who registers their own domain can publish perfectly valid SPF, DKIM and DMARC records for it. Authentication proves a message really came from the domain it claims. It never proves that domain is the one you meant to trust.
What it flags
Sender domains that are punycode or near-misses for a well-known brand; a brand name sitting in the display name while the address belongs to someone else; a Reply-To that would send your answer to a different domain than the one that wrote to you; links whose visible text and real target disagree; a Received chain whose hops or timestamps do not fit the story the From line tells; and the urgency, threat and credential-request language that pretexts are built from.
What it cannot tell you
It makes no network requests, so it cannot resolve a domain, look up an SPF record, re-verify a DKIM signature, or check a link against a blocklist. It reads what is in front of it. Headers below the topmost one can be forged by whoever sent the message, and legitimate mail from marketing platforms trips several of these flags routinely. Treat the result as a reading, not a verdict — the point is to show you which part of the message to look at, and why.
Nothing you paste leaves your browser
The parsing happens in this page, on your machine. There is no upload, no account, and no server to send anything to; the page makes no network request carrying any part of what you typed. Our analytics records that the tool was used and which of three coarse results it reached, and never sees the email. If the message you are holding is a real one sent to a real person, that matters.
If an account has already been phished, what to do in the next hour is the thing to read next, and passkeys vs passwords vs 2FA covers which of these attacks each control actually stops.