[{"data":1,"prerenderedAt":34},["ShallowReactive",2],{"tool-guide:email-header-analyzer":3},{"overview":4,"whatIs":5,"useCases":6,"steps":12,"example":16,"limitations":20,"faq":24},"Email Header Analyzer locally unfolds and decodes raw message headers, extracts reported SPF, DKIM, DMARC, and ARC results, reconstructs Received hops, and highlights details worth reviewing.","Every email message carries a set of headers that record its journey from sender to recipient. These headers include the sender and recipient addresses, subject line, timestamps, and — most importantly for troubleshooting — the Received headers that trace each mail server the message passed through, and the Authentication-Results headers that record whether SPF, DKIM, and DMARC checks passed or failed. Email headers are the primary diagnostic tool for investigating delivery problems, phishing attempts, spoofing, and authentication failures. However, raw headers are dense, multi-line, and encoded in formats like RFC 2047 that are not human-readable. This analyzer unfolds continuation lines, decodes encoded words, reconstructs the delivery path from Received headers (with timing between hops), and extracts authentication results into a clear summary. All parsing happens locally in your browser — your email headers (which may contain internal server names and IP addresses) are never uploaded.",[7,8,9,10,11],"Investigating phishing emails — inspect Authentication-Results to see if SPF, DKIM, and DMARC passed or failed, and check whether the Reply-To domain matches the From domain.","Diagnosing delivery delays — reconstruct the delivery path from Received headers and calculate the time spent at each hop to identify where delays occurred.","Verifying email authentication — confirm that your domain's outgoing emails pass SPF, DKIM, and DMARC checks at the receiving server.","Tracing email routing — follow the Received headers to understand which servers handled the message, useful for debugging relay and forwarding configurations.","Auditing ARC (Authenticated Received Chain) — inspect ARC headers that preserve authentication results across forwarding hops.",[13,14,15],"Copy the complete raw headers from your mail client and paste them into the analyzer.","Review the reported authentication assertions, delivery hops, timing, and domain observations.","Confirm suspicious findings with the receiving mail system or domain owner; header text alone is not proof of authenticity.",{"label":17,"input":18,"output":19},"Inspect a synthetic delivery","From, Reply-To, Authentication-Results, and two Received fields using example.com domains","SPF, DKIM, and DMARC reported pass · two delivery hops · Reply-To domain review",[21,22,23],"Header fields can be forged; StackCache parses reported evidence but does not independently verify signatures, DNS policy, or sender identity.","RFC 2047 UTF-8, ASCII, Latin-1, and Windows-1252 display words are decoded; unsupported encodings remain unchanged.","Input is limited to 256 KiB and content after the first blank line is ignored.",[25,28,31],{"question":26,"answer":27},"How do I get the raw email headers?","In Gmail, open the message, click the three-dot menu, and choose \"Show original.\" In Outlook, open the message properties. Other clients have similar options — search for \"view source\" or \"show headers.\"",{"question":29,"answer":30},"What authentication results does the tool check?","It extracts reported SPF, DKIM, DMARC, and ARC results from Authentication-Results headers. These are the assessments the receiving mail server recorded, not independent verification.",{"question":32,"answer":33},"Is my email content analyzed?","No. Only headers are parsed. Anything after the first blank line (the message body) is ignored. All analysis runs locally in your browser.",1788868141394]