Email Header Analyzer & Sender IP Tracer

Got a suspicious email or a deliverability problem? Paste the raw headers (the "Show original" output) and get a clean breakdown: sender, routing chain, and SPF/DKIM/DMARC verdicts.

—
Embed this tool on your website / blog No code required · Copy and paste
HTML Embed Code (iframe):
<iframe src="https://lucentool.com/email-header-parser" width="100%" height="650" style="border:1px solid #e5e0d8;border-radius:12px;max-width:850px;width:100%;" frameborder="0"></iframe>
<div style="font-size:12px;color:#78716c;margin-top:6px;font-family:sans-serif;">Powered by <a href="https://lucentool.com/email-header-parser" target="_blank" style="color:#c85a32;text-decoration:none;">Lucentool - Email Header Analyzer & Sender IP Tracer</a></div>

What headers tell you

Every email carries a stack of headers. The Received headers, added by each mail server, form a routing chain — read them top to bottom for the full path (the last one is the original sender's server). Authentication-Results headers carry the receiving server's SPF/DKIM/DMARC verdicts, which is where phishing triage usually starts.

Reading the verdicts

How to get raw headers

Gmail: open the message → ⋮ → Show original. Outlook: ⋮ → View → View message source. Apple Mail: View → Message → Raw Source. Paste everything from Delivered-To or Return-Path onward.

This parser is heuristic — for forensic certainty, correlate with DNS records yourself. It never uploads your headers; everything is parsed locally.