Email header analyzer

Paste the raw headers from any email to trace its delivery path hop by hop, see where time was lost, read the SPF, DKIM and DMARC verdicts the receiving server recorded, and check whether the From domain aligned. Parsed entirely in your browser; nothing is uploaded.

Gmail: open the message, ⋮ → Show original. Outlook: ⋯ → View → View message source. Apple Mail: View → Message → All Headers. Copy everything above the message body.

How it works

Reading a header block

Every server that handles a message stamps a Received header on top of the stack, so the raw headers read newest first. This analyzer reverses them into delivery order, works out the delay at each hop, and picks out the sending server's IP. A single hop holding mail for minutes usually means greylisting or a backed-up queue.

The receiving server records its authentication verdicts in Authentication-Results. Trust only the topmost one: it was added by your own provider. Anything below it is ordinary text that the sender could have written, including a forged "pass".

Authentication results

SPF, DKIM, DMARC and ARC verdicts as the receiver saw them at delivery time.

Alignment

Whether the SPF domain or a DKIM signing domain matches the From domain, which is what DMARC actually checks.

Delivery path

Each hop from origin to mailbox, oldest first, with the time it spent there.

DKIM signatures

Signing domain, selector and algorithm, with a link to check each key.

Bulk-sender basics

Message-ID, a sane Date, and one-click unsubscribe (List-Unsubscribe plus List-Unsubscribe-Post), which Gmail and Yahoo require.

FAQ

Common questions.

SPF passes but DMARC fails. Why?

Alignment. SPF passed for the Return-Path domain, but that is your platform's domain, not your From domain. DKIM-sign as your own domain, or set up a custom return path, and DMARC will pass.

There is no Authentication-Results header.

Messages copied from a Sent folder, drafts, and some internal mail never pass through a receiving server's checks. Analyze a copy you received in another mailbox instead.

Why do some delays look negative?

One of the servers has a wrong clock or time zone. Delays around that hop are unreliable; the rest of the path is still accurate.

Is my message uploaded?

No. Parsing happens in your browser and nothing leaves it.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call analyze_headers, or hit the JSON endpoint directly. No key, no account.

email-header-analyzer.sh
curl -X POST https://powerline.ai/api/tools/headers \
  -H "Content-Type: text/plain" \
  --data-binary @headers.txt
More free tools

Keep going.

EML Viewer

Open .eml and .emlx files in the browser: rendered body, headers, authentication and attachments.

IP Blacklist Checker

Check a sending IP against 18 email DNS blacklists, grouped by how much each one matters.

DKIM Checker

Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools