Email Header Analyzer: Trace Phishing Hops, SPF, DKIM & DMARC (2026)

Paste raw RFC 5322 email headers to decode SMTP relay hops, transit delays, Authentication-Results (SPF/DKIM/DMARC), and From vs Return-Path spoofing anomalies.

Phishing Email Header & SPF/DKIM/DMARC Analyzer — Interactive Console
Runs locally in your browser • Instant output
Paste Raw RFC 5322 Message Headers
Phishing Risk Score
100/100
High Spoofing Risk
SPF Verdict
softfail
RFC 7208 / 6376 / 7489
DKIM Signature
fail
RFC 7208 / 6376 / 7489
DMARC Alignment
fail
RFC 7208 / 6376 / 7489
Detected Header Spoofing Indicators
SPF authentication returned 'softfail'
DKIM cryptographic signature verification failed
DMARC alignment failed against organizational From header
Return-Path domain (mailer-) mismatches From domain (microsoft-security-alert.com)
Reply-To domain (protonmail.com) redirects replies away from From domain (microsoft-security-alert.com)
Envelope & Addressing Breakdown
From: "Microsoft 365 Security Team" <security-update@microsoft-security-alert.com>
Return-Path: <bounces@mailer- shady-promo88.ru>
Reply-To: "Urgent Helpdesk" <collect-credentials@protonmail.com>
Message-ID: <9981234.fake@mail-relay-untrusted.biz>

Reconstructed SMTP Received Hop Trace (Bottom-to-Top)

Hop #1: mail-relay-untrusted.biz → mx.enterprise.example.com
from mail-relay-untrusted.biz ([185.220.101.45]) by mx.enterprise.example.com with ESMTPS id 7721F Mon, 28 Sep 2026 06:42:02 +0000
Hop #2: mx.enterprise.example.com → inbox.enterprise.example.com
from mx.enterprise.example.com (mx.enterprise.example.com [10.20.0.15]) by inbox.enterprise.example.com with ESMTP id 9912A Mon, 28 Sep 2026 06:42:19 +0000
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Phishing Email Header & SPF/DKIM/DMARC Analyzer](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/email-header-analyzer/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/email-header-analyzer/">Phishing Email Header & SPF/DKIM/DMARC Analyzer — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Phishing Email Header & SPF/DKIM/DMARC Analyzer

Quick Answer & 2026 Technical Summary (email header analyzer)Updated 2026 Standard

Look for three red flags: (1) Authentication-Results showing spf=fail/softfail or dmarc=fail, (2) a Reply-To or Return-Path domain that differs from the visible From domain, and (3) an originating Received IP belonging to an unrelated hosting provider. Use this interactive email header analyzer above to test phishing header decoder, spf dkim dmarc header check, and trace email sender ip locally in your browser with zero server uploads.

Target Keyword Spec: email header analyzer | Modules: SPF, DKIM & DMARC Authentication Parser • Sender Alignment & Reply-To Mismatch Detector • Chronological SMTP Hop & Delay Tracer
Primary Focus: email header analyzer
Core Capability: phishing header decoder
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
SPF, DKIM & DMARC Authentication Parserphishing header decoderExtracts Authentication-Results and Received-SPF headers to show pass/fail/...SOC Phishing Triage
Sender Alignment & Reply-To Mismatch Detectorspf dkim dmarc header checkFlags display-name spoofing where From:, Return-Path:, and Reply-To: domain...Email Deliverability Debugging
Chronological SMTP Hop & Delay Tracertrace email sender ipReconstructs the exact path across Received: relays with hop-by-hop latency...SOC Phishing Triage
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is Phishing? Spear-Phishing, Email Spoofing & Prevention Guide

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Phishing Email Header & SPF/DKIM/DMARC Analyzer

01

Copy Raw Email Headers

In Gmail click 'Show original', or in Outlook/Apple Mail view 'Message Source', and copy the header block.

02

Paste Headers or Load Sample Phishing Header

Paste the raw headers into the analyzer (or click Load Phishing Sample to test a simulated attack).

03

Check Risk Score & Authentication Badges

Review the 0–100 Phishing Risk Score, SPF/DKIM/DMARC badges, and Return-Path/Reply-To domain alignment.

04

Inspect SMTP Relay Timeline

Examine each Received hop from originating IP to final mailbox delivery.

Key Capabilities & Technical Architecture

SPF, DKIM & DMARC Authentication Parser

Extracts Authentication-Results and Received-SPF headers to show pass/fail/softfail verdicts instantly.

Sender Alignment & Reply-To Mismatch Detector

Flags display-name spoofing where From:, Return-Path:, and Reply-To: domains diverge.

Chronological SMTP Hop & Delay Tracer

Reconstructs the exact path across Received: relays with hop-by-hop latency calculations.

100% Local RAM Processing

Confidential corporate email headers never leave your browser—zero server transmission.

Practical Use Cases

SOC Phishing Triage

Inspect suspicious executive impersonation or invoice emails without uploading private headers to third-party servers.

Email Deliverability Debugging

Diagnose why legitimate transactional emails are landing in spam or failing DKIM alignment.

Frequently Asked Questions (FAQs)

How can I spot a phishing email in raw headers?+

Look for three red flags: (1) Authentication-Results showing spf=fail/softfail or dmarc=fail, (2) a Reply-To or Return-Path domain that differs from the visible From domain, and (3) an originating Received IP belonging to an unrelated hosting provider.

Why are Received headers read from bottom to top?+

Every mail transfer agent (MTA) prepends its own Received: line to the top of the header block. Therefore, the bottom-most Received: header represents the earliest hop closest to the sender.

Can an attacker forge the From header?+

Yes. In raw SMTP, the DATA From: header is trivial to spoof unless the receiving server enforces DMARC alignment against valid SPF and DKIM cryptographic signatures.

Are my pasted email headers uploaded anywhere?+

Never. All regex parsing and hop timestamp calculations execute strictly inside your browser's JavaScript engine.

What does dmarc=fail (p=quarantine) mean?+

It means the message failed both SPF and DKIM domain alignment, and the domain owner's DMARC policy instructed your mail provider to quarantine the message into the Spam/Junk folder.