U
UtilyxHub
Header Forensics ← All Tools
🛡️ 100% In-RAM Header Linter • SPF / DKIM / DMARC Validator • Zero Server Telemetry

Email Header Security & Authentication Linter

Inspect raw RFC 822 email headers. Validate SPF, DKIM, and DMARC alignment, trace MTA relay hops, and detect sender spoofing.

Raw RFC 822 Email Headers (.eml content)
Presets: | |
0 lines • 0 bytes
SPF Authentication UNCHECKED

Sender Policy Framework

DKIM Signature UNCHECKED

Cryptographic Integrity

DMARC Alignment UNCHECKED

Domain Policy Alignment

Email Authenticity Assessment
Awaiting Email Headers
Status: N/A

Paste full RFC 822 email headers above to extract authentication results, audit Return-Path alignment, and trace mail transfer agent hops.

Extracted Header Fields Core Metadata
Paste headers above to parse fields.
Relay Hops Trace (Received Chain) 0 Hops Identified
No relay hops extracted yet.
RFC 5322 Standard Compliance 100% In-RAM

Email Authentication Standards (SPF vs. DKIM vs. DMARC)

How modern mail transfer systems prevent identity spoofing.

Protocol Primary Function Failure Implication
SPF (Sender Policy Framework) Authorizes sending server IP addresses via DNS TXT records. The message originated from an unauthorized IP server not owned by the sender.
DKIM (DomainKeys Identified Mail) Cryptographically signs the email body and headers with a private key. The email body or headers were altered or forged in transit by an intermediary.
DMARC (Domain-based Message Auth) Specifies what receivers must do if SPF/DKIM fail (reject, quarantine, or none). The sender identity is misaligned with the authenticated envelope domain.

Understanding RFC 822 Email Headers & Spoofing Detection

The display name and "From" address visible inside consumer email apps (like Apple Mail or Gmail) are easily forged by malicious mail servers. To verify the true authenticity of an incoming email, one must inspect the underlying RFC 822 transmission headers.

1. How to Trace Received Hop Chains

Every mail transfer agent (MTA) that relays an email appends a new Received: header at the very top of the header stack. By reading these hops in reverse order (bottom to top), one can trace the exact geographical IP address, hostname, and latency where the message first originated.

🔗 Phishing URL Inspector

Audit suspicious links inside emails with Phishing URL Inspector.

🛡️ Universal Scam Detector

Triage social engineering traps with Universal Scam Detector.

Frequently Asked Questions

Where do I find raw email headers in Gmail?

Open the email in Gmail, click the three vertical dots in the upper-right corner of the message, and select "Show original". Copy the header text displayed.

Is my email content uploaded to any server?

Never. All header parsing, cryptographic signature extraction, and hop tracking execute 100% locally in your device's browser memory (RAM).