Free Email Header Analyzer - Decode Received Chain | BounceZero
Free - Private - Not Logged

Email Header Analyzer

Paste raw email headers and decode the Received chain, SPF/DKIM/DMARC results, hop delays, and sender IP. Nothing is logged.

Max 64 KB. Processed in-memory. Body content (after first blank line) is ignored.

Research context: in our census of 272,446 commercially mailed domains, 62.7% published DMARC but only 13.4% enforced it. The header shows whether an individual message actually authenticated. Read the 2026 infrastructure report.

What This Tool Does

Email headers are the technical metadata at the top of every message - From, To, Subject, plus a stack of Received lines showing every server the message passed through, plus authentication results (SPF, DKIM, DMARC). Most email clients hide them by default. When something goes wrong with deliverability, the headers are where the answer lives.

This tool parses raw headers and surfaces the key information: who sent it, what path it took, how long each hop took, whether authentication passed, what the originating IP was, and any obvious red flags. No signup, no logging, no storage - paste headers, get analysis, close the tab.

How to Get Raw Headers

What Each Section Tells You

Want to understand SPF/DKIM/DMARC results in depth?

Our complete email authentication guide explains exactly what each result means, the alignment rules that decide DMARC, and how to fix common failures.

Read the SPF/DKIM/DMARC guide

Frequently Asked Questions

How do I analyze an email header?

Open the original message source in Gmail, Outlook, Apple Mail, Yahoo, or Thunderbird; copy the raw headers; and paste them into the analyzer. It unfolds the Received chain, extracts the originating IP, calculates hop delays, and reads SPF, DKIM, DMARC, ARC, Return-Path, and Message-ID fields without storing the content.

Why are timestamps in the Received chain different from each other?

Each mail server records when it received the message using its own clock. The differences between chronological hops reveal delivery delay. Most hops take under a second; longer delays can indicate greylisting, throttling, queueing, or a backlogged relay.

Why does my email header not show a Received chain?

You may have copied only the visible From, To, and Subject fields instead of the full raw source, or analyzed a forwarded copy that no longer contains the original chain. Use Show Original or View Message Source on the original message.

What does SPF, DKIM, or DMARC "not present" mean?

Either the sending domain did not publish or apply that authentication method, or the receiving server did not include its result in Authentication-Results. If you control the domain, verify that SPF and DKIM pass with alignment before enforcing DMARC.

Is the originating IP always the actual sender?

It is the first public IP in the chronological Received chain. For mail sent through an ESP, that address belongs to the ESP relay; for directly sent mail it is usually the sender infrastructure that mailbox providers evaluate for IP reputation.

Does the email header analyzer store my headers?

No. Headers are processed in memory for the current request and are not logged or retained. Parsing also stops at the first blank line, so the message body is ignored even if it is pasted accidentally.

More Free Tools

Free tools & checkers

Single-email checks, no signup required