Skip to main content
Back to all tools
SOC Mail Investigation

Phishing Email Header Analyzer

Dissect raw RFC 822 email headers to trace MTA hop latencies, inspect SPF/DKIM/DMARC authentication results, and expose spoofed sender identities.

Use ResponsiblyLocal Browser Execution

Only assess raw RFC 822 email headers you own or have explicit authorization to test. This tool is intended solely for defensive security analysis, posture auditing, and authorized assessment.

Local Execution: 100% in-browser client-side parsing. Zero email content, headers, addresses, or logs are uploaded or transmitted to any server.

Non-Destructive: No exploitation, brute-forcing, or state-altering requests are performed.Responsible Use Policy
Load scenario:···
Tip: In Outlook, open email > File > Properties > Internet headers. In Gmail, click "Show original".
Community Supported Free Tooling

Find Phishing Email Header Analyzer helpful? Buy me a coffee!

All tools run without ads, telemetry tracking, or paid subscriptions. If this saved you time during an incident triage, header audit, or threat hunt, a small coffee contribution helps keep the servers alive and fuels new tool development.

Technical Limitations & Operational Caveats

Email header timestamps are recorded by individual Mail Transfer Agents (MTAs) and rely on local server clocks. Minor clock drift or timezone differences can skew hop latency metrics. Verification of SPF and DKIM verifies sender authorization and header integrity; it does not inspect attachment payloads or dynamic sandbox behaviors.