Is this email really legitimate?

Paste the full header of a suspicious email. We analyze it and explain, in plain language, whether you should be wary — even when everything looks “authenticated”.

Free, no signup. Local analysis, nothing is stored.

🔎In-depth AI analysisPRO

An AI analyst scrutinizes the header (hijacked Reply-To, look-alike domains, routing inconsistencies…) and gives you a trust score out of 100, the signals explained, and what to do.

What is this tool for?

Got a weird email and wondering if it's a scam? This analyzer reads the message's technical header — the invisible part that reveals where it truly comes from — and gives you a clear, jargon-free verdict.

Why “authenticated” doesn't mean “trustworthy”

This is the crux. SPF, DKIM and DMARC check one thing only: that the email really comes from the domain listed as the sender. They say nothing about whether that domain is honest. A fraudster registers a throwaway domain, wires up these protections in five minutes, and their email shows up “all green”. The impersonation happens elsewhere: a display name spoofing a well-known company, sending through a bulk email service, a domain with no relation to the message.

What the analysis catches

SPF / DKIM / DMARC results, domain alignment, mismatch between the display name and the real domain, brand impersonation, the sending service used, origin IP addresses, and the “external” tag added by your mail system. All summed up in a 🟢 / 🟠 / 🔴 verdict.

To protect your own business against spoofing, run the free security check of your domain instead.

Frequently asked questions

How do I find an email's header?

In Gmail: open the email → ⋮ menu → “Show original”. In Outlook (desktop): open the email → File → Properties → “Internet headers”. In Apple Mail: View → Message → “All Headers”. Copy everything and paste it here.

If SPF, DKIM and DMARC pass, is the email trustworthy?

No — and that's the most common trap. These three protections only prove the email really comes from the domain in the sender field, not that it's honest. A fraudster who buys a throwaway domain sets up SPF, DKIM and DMARC correctly and passes every check. The fraud then hides in the display name, the sending service and the content.

Is my data kept?

No. The analysis runs on the fly and nothing is stored. We still recommend masking personal information before pasting a header into any tool.

What if the result is “red”?

Don't click any link, don't reply and don't pay. If the message claims to come from a supplier, a bank or a colleague, verify through another channel (phone, official site typed by hand). Then delete the email and, at work, report it to your IT lead.