---
title: "Email Header Analyzer"
description: "Paste email headers to trace the routing path, extract sender IPs with geolocation, and check SPF, DKIM, and DMARC authentication results. online email forensics tool."
url: https://findutils.com/network/email-header-analyzer/
category: network
---

# Email Header Analyzer

Paste email headers to trace the routing path, extract sender IPs with geolocation, and check SPF, DKIM, and DMARC authentication results. online email forensics tool.

**Use this tool:** [Email Header Analyzer](https://findutils.com/network/email-header-analyzer/)

## Programmatic access

- REST id `email-header-analyzer`: POST https://api.findutils.com/api/tools/email-header-analyzer/execute (reference: https://findutils.com/api/email-header-analyzer/)
- MCP tool `email_header_analyzer` on https://mcp.findutils.com (reference: https://findutils.com/mcp/email-header-analyzer/)

## Why Analyze Email Headers?

Email headers contain the complete routing history of a message, from sender to recipient. By analyzing these headers, you can trace the geographic path an email took, verify authentication (SPF, DKIM, DMARC) to detect spoofing, identify the sender's real IP address, and diagnose delivery issues. This is essential for security investigations, phishing detection, and email deliverability troubleshooting.

## Tips for Email Header Analysis

- Always copy the FULL headers, not just the visible portion. Partial headers may miss important routing information.
- Read the Received headers from bottom to top. The bottom entry is the originating server, and each subsequent entry is a hop along the delivery path.
- SPF, DKIM, and DMARC should all show 'pass' for legitimate emails. Any 'fail' result is a red flag.
- Multiple IPs from different countries in the routing path can indicate email forwarding or relay chains, but can also indicate suspicious routing.
- The sender's real IP is usually in the first (bottom-most) Received header. Headers added by intermediate servers are above it.

## Frequently Asked Questions

### What are email headers?

Email headers are metadata attached to every email message. They contain technical information about the sender, recipient, routing path, timestamps, and authentication results. Headers are normally hidden but can be viewed through your email client's settings.

### Can email headers reveal the sender's real IP?

Yes, in many cases. The originating IP is typically in the first Received header. However, if the sender used a webmail service (Gmail, Outlook), the IP will be the mail service's server, not the sender's personal IP.

### What do SPF, DKIM, and DMARC mean?

SPF verifies the sender's server is authorized to send email for that domain. DKIM verifies the message wasn't tampered with using a digital signature. DMARC combines both and tells receiving servers what to do when checks fail. All three should show 'pass' for legitimate email.

### Is this tool safe to use with sensitive emails?

Yes, with one caveat. Parsing happens in your browser, and the email headers themselves are not sent to any server. The only external requests are geolocation lookups to ip.findutils.com, which receive the IP addresses found in the headers, up to ten per analysis; that FindUtils service keeps standard request logs.

### Why are there so many hops in my email?

Each hop represents a mail server that processed the email. Typical emails have 3-5 hops. More hops can indicate email forwarding, mailing list processing, or security filtering. While not necessarily suspicious, unusual routing should be investigated.

## Related Tools

- [IP Address Lookup](https://findutils.com/network/ip-address-lookup/)
- [DNS Lookup](https://findutils.com/network/dns-lookup/)
- [DNS & WebRTC Leak Test](https://findutils.com/network/dns-leak-test/)
- [Email Validator](https://findutils.com/security/email-validator/)
- [Security Headers Analyzer](https://findutils.com/network/security-headers-analyzer/)
