100% client-side · nothing leaves your browser

Find out why your email lands in spam.

Paste a raw header and get the answer with the fix: authentication, alignment, where the provider recorded it landing, blocklists, and what each requirement of Gmail, Yahoo and Microsoft actually says about this message. Every finding comes with a recommended action and the source it rests on.

raw-header.txt
SPFDKIMDMARC
Delivered-To:you@yourdomain.com
Received:from mail-sor-f41.google.com (209.85.220.41)
by mx.yourdomain.com with ESMTPS id 4f2a9c
(TLS1_3 / AEAD-CHACHA20-POLY1305); Tue, 12 Mar 2024
ARC-Authentication-Results:i=1; mx.google.com;
spf=pass dkim=pass dmarc=pass
Authentication-Results:mx.yourdomain.com;
spf=pass (sender IP is 209.85.220.41)
dkim=pass header.d=notify.example.com
dmarc=pass action=none header.from=example.com
From:Example Notifications <no-reply@example.com>
Subject:Your monthly statement is ready
analyzed locally in 12ms
No signup
No data stored
Open source friendly
Works offline

Everything in one pass

Everything you need to trust an email

Authentication, routing, reputation, delivery evidence and complaint readiness — all from a single pasted header, all in your browser.

SPF / DKIM / DMARC authentication

Verify all three mechanisms at once, see every DKIM signature separately, and get alignment judged against the domain’s own published policy — not a fixed assumption.

Delivery path timeline

A hop-by-hop timeline showing each relay, per-hop delay, and TLS encryption detection so you can see exactly where a message slowed down.

Forefront Antispam decoder

Decodes Microsoft 365 Forefront reports — SCL, PCL and BCL scores plus the IP filter verdict — into plain, readable language.

Blacklist & reverse-DNS lookup

Optional IP/domain blacklist checks with PTR and reverse-DNS resolution to confirm the sending infrastructure is legitimate.

DNS policy checker

Inspect published DMARC/SPF/DKIM policies and alignment modes, the SPF lookup limit, and DNSSEC, DANE, MTA-STS, TLS-RPT and BIMI in one pass.

Trust score gauge

A single A–F grade backed by plain-language findings, so anyone can understand how trustworthy a message really is.

Recorded delivery destination

When Microsoft stamps where a message actually landed, the tool reports Inbox, Junk or quarantine as recorded fact — and explains which signal put it there — instead of guessing from a spam score.

Complaint feedback & provider readiness

Checks List-Unsubscribe, one-click unsubscribe (RFC 8058), Feedback-ID and CFBL-Address (RFC 9477), then says what can honestly be concluded for Gmail, Yahoo, Microsoft and Apple.

PDF report with shareable QR

Export any analysis as a PDF with the sections you choose. It ends with a QR code that opens the summary on a phone — the link carries the summary only, never the raw headers.

Three steps

From raw header to clear answer

Step 1

Paste header

Copy the raw source of any email and drop it into the analyzer. Nothing is uploaded.

Step 2

Instant analysis

Every parser runs locally in your browser in milliseconds — even with no connection.

Step 3

Get score & findings

Read an A–F trust grade with clear, actionable findings and a full delivery breakdown.

The dashboard

See the whole picture at once

Trust score, authentication results and delivery path — laid out so the answer is obvious at a glance.

mailauth · report
B88/100

Good, with one thing to fix — the score explains which, and what it could not measure.

SPFpass

passes, and the checked domain is a subdomain of the From domain — aligned under the relaxed mode this domain publishes.

DKIMpass

two signatures. The brand’s aligns and passes, which is all DMARC needs; the platform’s does not align, which is ordinary.

DMARCwarn

passes, but the policy is p=none — publishing it is not the same as enforcing it.

  • mta-11.esp-platform.example.netTLS 1.3 · 0.4s
  • mx.google.comTLS 1.3 · 0.1s
  • internal-relay-02no TLS evidence · 1.2s