Free tool Stays in your browser No signup

Is this email legit?
Read the headers

Paste the technical headers from a suspicious message. We’ll translate SPF, DKIM, DMARC, Reply-To tricks, and other signals into plain English.

What you’ll see
SPF · DKIM · DMARC

Authentication results explained without the jargon dump.

Reply-To & spoof signals

Common tricks that look fine in the body but fail in the headers.

Local analysis

Runs in your browser — we don’t upload your headers to Network26.

SPF DKIM DMARC Reply-To
Plain English. No signup.
ANALYZE

Your headers

From “Show original” / message details — not just the email body.

HOW TO GET HEADERS

Copy the technical view, not the body

You need the hidden routing and authentication lines. Here’s the short path in common apps.

1

Outlook (Microsoft 365)

Open the message in its own window → FileProperties (or right‑click it in your inbox → Properties). Copy everything in the Internet headers box at the bottom.

2

Gmail

Open the message → next to Reply, click More () → Show original. Click Copy to clipboard (or select all in that window and copy).

3

Apple Mail

Open the message → ViewMessageRaw Source (or All Headers on some versions). Select all and copy the header block at the top.

WHAT WE LOOK FOR

Signals that matter for SMBs

Authentication-Results (SPF / DKIM / DMARC)

Your provider’s verdict on whether the sender’s domain checks out. A DMARC pass is a strong sign the From: domain is aligned. A fail is a reason to slow down.

From vs Reply-To

Looks like your vendor or CEO, but replies go to a totally different address? That’s a classic invoice / wire-fraud pattern.

Display-name tricks

The friendly name in your inbox can lie. We flag when the display name embeds a different email than the real From: address.

Also try our DMARC domain checker and spoof preview.

Suspicious mail still landing?

We help Puget Sound teams lock down email authentication, reduce spoof risk, and get same-day help when something looks wrong.