Paste the technical headers from a suspicious message. We’ll translate SPF, DKIM, DMARC, Reply-To tricks, and other signals into plain English.
Authentication results explained without the jargon dump.
Common tricks that look fine in the body but fail in the headers.
Runs in your browser — we don’t upload your headers to Network26.
You need the hidden routing and authentication lines. Here’s the short path in common apps.
Open the message in its own window → File → Properties (or right‑click it in your inbox → Properties). Copy everything in the Internet headers box at the bottom.
Open the message → next to Reply, click More (⋮) → Show original. Click Copy to clipboard (or select all in that window and copy).
Open the message → View → Message → Raw Source (or All Headers on some versions). Select all and copy the header block at the top.
Your provider’s verdict on whether the sender’s domain checks out. A DMARC pass is a strong sign the From: domain is aligned. A fail is a reason to slow down.
Looks like your vendor or CEO, but replies go to a totally different address? That’s a classic invoice / wire-fraud pattern.
The friendly name in your inbox can lie. We flag when the display name embeds a different email than the real From: address.
Also try our DMARC domain checker and spoof preview.
We help Puget Sound teams lock down email authentication, reduce spoof risk, and get same-day help when something looks wrong.