Header Analyzer: find out where an email really came from
Someone forwards you a suspicious invoice and asks "is this real?". The answer is in the email's headers, which are unreadable to most people. Paste them here and get a verdict in plain words.
- Where to find it
- Inspect → Header Analyzer
- Who can use it
- Organization Admin, Organization User (not Viewer)
- Time needed
- 1 minute
Getting the headers
Gmail: open the email → the three dots at the top right → Show original. Copy everything.
Outlook (web and desktop): open the email → the three dots → View message source (or View → Message details in older versions).
What you get back
- An overall verdict: safe, warning or danger, plus a 0 to 100 confidence score for the sender's identity.
- A plain-language summary of who actually sent the message and whether that's verified.
- The hop-by-hop path the message took, with each server's location and whether it's on a blacklist.
- Pass or fail for SPF, DKIM, DMARC and ARC (the standard that preserves authentication through forwarding).
- Where available, what the receiving end did: TLS encryption and the spam filter's verdict.
The headers are all the tool needs. If the email body contains something sensitive, leave it out and paste the headers alone.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.