Back to Tools

Email Header Analyzer

Analyze email headers to trace routing, check authentication (SPF, DKIM, DMARC), identify delivery delays, and debug email issues. Paste headers from any email client.

About this tool

When an email goes missing, lands in spam, or takes 10 minutes to arrive, the headers hold every answer you need. Email headers are metadata that every mail server adds as your message hops from sender to recipient. They record authentication results, server timestamps, IP addresses, and routing decisions. Paste your headers into this analyzer and you'll see exactly what happened — and where things went wrong.

What's actually in email headers

Every email carries a stack of headers that gets built bottom-up as the message travels. The oldest headers are at the bottom, the newest at the top. Key headers include: Received (one per server hop, with timestamps), Authentication-Results (SPF, DKIM, DMARC verdicts), From and Return-Path (which may differ — that's important), Message-ID (unique identifier), and X-Spam-Status (spam filter scores). Our analyzer parses all of these and presents them in a readable timeline.

Debugging authentication failures

The most common reason emails hit spam is authentication failure. The Authentication-Results header tells you exactly which checks passed or failed. If SPF failed, the sending IP isn't in your SPF record. If DKIM failed, the signature couldn't be verified — maybe the DNS record is wrong or the message was modified in transit. If DMARC failed, neither SPF nor DKIM aligned with your From domain. This analyzer highlights failures in red so you can spot them instantly.

Finding delivery delays

Each Received header includes a timestamp. By comparing consecutive timestamps, you can pinpoint exactly where your email sat waiting. A 200ms gap between hops is normal. A 45-second gap means that server was doing something slow — probably spam filtering or greylisting. If you see delays of 5+ minutes, the receiving server might be applying rate limits to your IP, which often happens during email warmup.

Common header analysis mistakes

Don't confuse the From header with the Return-Path (envelope sender). They're often different, and SPF checks the Return-Path domain, not the From domain. Another mistake: assuming a "pass" on all three auth checks means your email will reach the inbox. Authentication is necessary but not sufficient — content filtering, sender reputation, and engagement history all play roles too. Check your domain against blacklists and run a deliverability score check for the full picture.

Frequently Asked Questions

How do I get email headers from my email client?

In Gmail: open the email, click the three-dot menu, select 'Show original'. In Outlook: open the email, click File > Properties, and look in the 'Internet Headers' box. In Apple Mail: View > Message > All Headers. In Thunderbird: View > Message Source. Each client puts it in a slightly different place, but they all have the option somewhere.

What do SPF, DKIM, and DMARC results in headers mean?

The Authentication-Results header shows whether each check passed or failed. 'pass' means the check succeeded. 'fail' means it definitively failed. 'softfail' (SPF only) means the sender isn't authorized but the domain owner hasn't set a hard policy. 'none' means no record was found. You want all three to show 'pass' — anything else increases your spam risk.

Why is there a big delay between two hops?

Each server in the chain adds a Received header with a timestamp. Large gaps usually mean the receiving server held the message for processing — spam filtering, greylisting (intentionally delaying first-time senders), virus scanning, or rate limiting. If you consistently see delays at the same hop, it's likely a policy on that specific server, not a network issue.

What's the difference between From and Return-Path?

The From header is what the recipient sees in their inbox — it's the display address. The Return-Path (also called envelope sender) is where bounces go, and it's what SPF checks against. They're often different, especially when using an ESP. For example, your From might be you@yourdomain.com while the Return-Path is bounce-123@esp.sendgrid.net. DMARC alignment requires that at least one of SPF or DKIM matches the From domain.

Can headers tell me why my email went to spam?

Headers give you strong clues but not always the complete answer. They'll show authentication failures (SPF/DKIM/DMARC), spam filter scores (X-Spam-Status), and whether the sending IP is flagged. But some spam decisions are based on content analysis, recipient engagement history, or sender reputation — those don't appear in headers. Start with headers for authentication issues, then check your domain reputation and content separately.

What does 'greylisting' mean in headers?

Greylisting is a spam prevention technique where the receiving server temporarily rejects the first delivery attempt from an unknown sender with a 'try again later' response. Legitimate mail servers retry after a few minutes and succeed. Spammers typically don't retry. You'll see it as a delay of 5-15 minutes between the first and second Received headers from the same server. It's annoying but normal for first-time senders.

How do I read the Received headers in order?

Received headers are added top-down, so the newest (last server to handle the email) is at the top and the oldest (the originating server) is at the bottom. Read them bottom-to-top to trace the message's journey chronologically. Our analyzer automatically sorts them into a timeline for you, so you don't have to read them backwards.

What's a normal number of hops for an email?

Most emails pass through 3-6 servers (hops). A typical path: your mail client to your outgoing server, to any intermediary filtering servers, to the recipient's MX server, to their spam filter, and finally to their mailbox. More than 8 hops is unusual and might indicate misconfigured routing or unnecessary relay servers.

Compare email marketing software

Hands-on roundups to help you pick the right platform.