How this works. This tool runs entirely in your browser: your pasted headers are parsed locally and never sent to us or stored. The one exception is the originating IP, which we look up for location and network owner via ipapi.co (only that IP address is sent, not your email). Header analysis shows what the mail servers recorded; a determined sender can forge some fields, which is exactly why the SPF, DKIM and DMARC results matter. For your own domain's email setup, use our Email Security Checker. For a complete review, talk to us.
// What this means for your business
One convincing email is all it takes
Reading headers tells you whether a single message is legitimate. Stopping the bad ones before anyone has to, with enforced DMARC, mail filtering, and a team that investigates the suspicious ones, is what protects a business day to day. That is what we do for small Canadian companies.