Skip to main content
Docs/Using the tools
Using the tools

Read an email header.

Decode the routing path of any message - delivery hops, authentication results, and origin.

4 min read · Updated May 2026

Every email carries a hidden technical record of how it travelled from sender to you - the header. When mail goes missing, lands in spam, or looks suspicious, the header is where the answer lives. Our Header Analyzer decodes it for you in plain English. Here's how to grab a header and read what it's telling you.

Step 1: Get the raw header

You need the raw header, not the friendly From/Subject you normally see. It's three clicks in any client:

  1. GmailOpen the message → the three-dot menu (top right) → Show original. Copy everything on that page.
  2. OutlookOpen the message → File → Properties (or the three-dot menu → View → message source). Copy the Internet headers box.
  3. Apple MailSelect the message → View → Message → Raw Source (or All Headers). Copy the lot.

Step 2: Paste it into the Analyzer

Open the Header Analyzer, paste the raw header into the box, and run it. No signup, no setup - it parses instantly in your browser.

Step 3: Read the three things that matter

The Analyzer breaks the header into a readable report. Three sections answer almost every question:

  1. The delivery path (hops)Each Received: line is one hop the message took between mail servers, shown oldest-to-newest. A long, slow, or geographically odd path can explain delays or flag a spoofed route.
  2. Authentication resultsThis is the big one for deliverability: did SPF, DKIM, and DMARC pass or fail? A fail here is the usual reason legitimate mail gets junked. If you're debugging your own sending, this tells you exactly which check broke.
  3. Origin & identityThe originating IP, the sending domain, and whether the From: aligns with the authenticated domain. Mismatches are a classic phishing and spoofing signal.

Debugging your own mail? If SPF/DKIM/DMARC show fail here, the fix is in your DNS, not the header. Run your domain through the CRM DNS Verifier or DNS Checker to see exactly what's misconfigured.

What a healthy header looks like

For mail you sent that's authenticating correctly, you want to see spf=pass, dkim=pass, and dmarc=pass in the authentication results, with the signing domain matching your From: domain. If all three pass and mail still lands in spam, the problem is reputation or content - check a blacklist sweep and spam score next.