Message headers record every server a message passed through and what each receiver thought of it. Paste them here to turn the wall of text into a readable path — parsed in your browser. Only the sending IP address and the domains are sent to our server, for live SPF, DKIM key and DMARC lookups; the headers themselves are not uploaded.
Table of Contents
Getting the headers
Gmail: open the message » three-dot menu » Show original. Outlook desktop: File » Properties » Internet headers. Outlook on the web: three-dot menu » View » View message source. Apple Mail: View » Message » All Headers. Copy everything above the message body.
The first hop is the sender’s own mail server or client; a long delay on a middle hop means that server queued the message, often because of greylisting, rate limits or a busy spam filter.
Email header analyzer at a glance



How to use this tool
- Open the original message (not a forwarded copy) and copy the full headers using the steps above. Pasting the whole message source also works: the analyzer stops at the first blank line, where the body starts.
- Paste the text into the box and press Analyze headers. Anything shorter than a few lines is rejected, because a single header is not enough to trace a message.
- Read the summary first: who sent it, which server handed it over, and the SPF, DKIM and DMARC verdicts.
- Then read the two tables: the authentication results each receiving server wrote down, and the delivery path from the oldest hop to the newest.
- If DKIM is the open question, send a fresh copy of the same kind of message to the email deliverability test. Headers alone cannot prove a DKIM signature, because the signature also covers the body.
Parsing happens in your browser. After parsing, the page sends only the sending IP, the Return-Path and From domains and up to four DKIM domain and selector pairs to our server, which looks up SPF, DMARC and the DKIM keys in DNS as they are now.
How to read the results
The summary only shows rows the headers actually contain. Each verdict is coloured: green for pass, red for fail, softfail and permerror, amber for anything in between such as neutral, none, temperror or a DMARC pass under p=none.
| Row | What it means |
|---|---|
| From, To, Subject, Date, Message-ID | Copied exactly as written by the sender. The From address is the one people see, and it is the domain DMARC protects. |
| Return-Path | The envelope sender (MAIL FROM) recorded by the last server. SPF is checked against this domain, not against From. |
| Sending server | The public IP that handed the message to the receiving system, with the HELO name it used. The analyzer reads the newest Received header that names an IP in square brackets, skipping LMTP and local delivery hops and private addresses. If this row is missing, the live SPF check is skipped. |
| SPF | The verdict the receiver recorded, then live check now: our own SPF evaluation of the same IP and Return-Path domain against the record published today, with the mechanism that matched. |
| DKIM | The recorded verdict, then every signature found (up to four) with its domain (d=), selector (s=), algorithm, whether the public key exists in DNS now and its size, and aligned with From when the signing domain matches the From domain. |
| DMARC | The recorded verdict. If the receiver did not record one, the analyzer works it out from the SPF and DKIM alignment and the policy published now. The policy (p=, and pct= below 100) is shown; a subdomain uses the parent’s sp= value when it has no record of its own. |
| Hops | How many Received headers the message collected. Large providers add several internal hops of their own, so a high count is not a problem by itself. |
| Total delay | The sum of the gaps between hop timestamps. It turns amber above 300 seconds. |
| Spam filter | The raw value of X-Spam-Status, X-Spam-Score, X-Microsoft-Antispam or X-Forefront-Antispam-Report, whichever comes first. |
| Alignment note | Shown when the From and Return-Path domains differ. SPF can then never align, so DMARC depends on a DKIM signature from the From domain. |
In the delivery path table the Protocol column shows how each hop was received. ESMTPS means TLS was used, ESMTPA means the client logged in, and ESMTPSA means both (RFC 3848). Plain SMTP or ESMTP between two servers means the hop was not encrypted. A negative delay means one server’s clock is wrong; it is shown but not added to the total.
Microsoft 365 and Outlook.com headers
Microsoft writes its verdict into X-Forefront-Antispam-Report and adds a compauth (composite authentication) result to Authentication-Results. The fields worth reading:
| Field | Meaning |
|---|---|
CIP | The connecting IP address. |
SFV | Spam filter verdict: NSPM not spam, SPM spam, SKA/SKI/SKN filtering skipped because of an allow list, IP allow list or mail flow rule. |
CAT | The category that decided the outcome, for example SPM, HSPM, BULK, PHSH or SPOOF. |
SCL | Spam confidence level from -1 to 9. Microsoft notes that in the cloud it no longer decides the verdict, so read SFV and CAT instead. |
compauth=fail reason=000 | DMARC failed and the domain’s policy is quarantine or reject. |
compauth=fail reason=001 | Implicit failure: the domain has no authentication records, or only weak ones such as ~all or p=none. |
compauth=pass reason=1xx | Authentication passed and aligned with the From domain. |
Common problems and how to fix them
“dkim=neutral (body hash did not verify)”
The signature header is intact but the body changed after signing. Typical causes are a mailing list or gateway that adds a footer or disclaimer, an antivirus scanner that rewrites links, or a relay that re-encodes the message. Sign on the last server that touches the message, or add footers before the DKIM signing step. Mail through mailing lists usually survives DMARC only when the list adds ARC headers or rewrites the From address.
“spf=softfail … does not designate 203.0.113.10 as permitted sender”
The IP that delivered the message is not in the SPF record of the Return-Path domain. Find out what sent it (the Sending server row), then add the provider’s include: or the server’s ip4: to the record. Check what is published now:
dig +short TXT example.com | grep spf1
“spf=permerror”
The receiver could not evaluate the record at all: the domain publishes two v=spf1 records, the syntax is broken, or evaluation needs more than 10 DNS lookups. Merge everything into one record and flatten includes you no longer use. See SPF too many DNS lookups.
DKIM key shows “NO key in DNS”
The selector named in s= has no public key published, so every receiver will fail the signature. Publish the key your mail server or provider shows, or switch signing to a selector that exists. On an old message this can also mean the key was rotated since; that is expected and harmless. To find which selector a sender uses, read find a DKIM selector.
dig +short TXT default._domainkey.example.com
One hop with a long delay
The server named in the By column of the slow hop held the message. Greylisting adds a few minutes on first contact; longer gaps point at a queue backlog, a rate limit at the next provider, or a server that could not reach the next hop and retried. On a cPanel or DirectAdmin server running Exim, search the log for the message:
exigrep 'example.com' /var/log/exim_mainlog
On Postfix servers the same lines are in /var/log/maillog (RHEL family) or /var/log/mail.log (Debian and Ubuntu).
No sending server is shown
Either the headers were cut off before the first external hop, or the message was submitted from a mail client on a private network and the provider did not record a public IP. Copy the headers again from the original message. A message you forwarded to yourself only shows the forwarding path, not the original sender.
BLOCKED rules in X-Spam-Status
Rules such as URIBL_BLOCKED mean the receiving SpamAssassin could not query a blacklist because it uses a public DNS resolver that the list refuses. The fix belongs on the receiving server (use a local caching resolver), not in your message.
Official documentation: DirectAdmin documentation, cPanel & WHM documentation, RFC 5321 (SMTP).
Related guides: Warm up a new mail server IP or sending domain without landing in spam · Configuring DirectAdmin’s Exim to relay through MailBaby · Choosing a VPS for a cPanel or DirectAdmin server in 2026.
Frequently asked questions
Is it safe to paste headers here?
The headers are parsed in your browser and are not uploaded. Only the sending IP address and the sender domains go to our server, so it can look up SPF, DKIM keys and DMARC live.
Why does DMARC fail when SPF passes?
SPF passed for the Return-Path domain, which differs from the From domain, so it is not aligned. Sign with DKIM for the From domain to fix it.
Where do I see the spam score?
Look for X-Spam-Status (SpamAssassin/cPanel), X-Rspamd-Score, or X-Forefront-Antispam-Report (Microsoft 365) in the results.
Which Received header shows the real sender?
Read from the bottom up: the lowest header is the oldest hop. Only headers added by servers you trust, usually your own provider at the top, are reliable; anything below the first hop your provider recorded can be forged by the sender.
Can email headers be faked?
The From, Reply-To and older Received lines can be written by anyone. That is why receivers record SPF, DKIM and DMARC results: a forged From address fails DMARC unless the sender controls the domain.
What is ARC-Authentication-Results?
ARC (RFC 8617) lets a forwarder or mailing list record the authentication results it saw before it changed the message. A later receiver can trust those results even though SPF or DKIM now fail.
Can I find where the sender is from the IP address?
Only roughly. The IP belongs to the sending server, which is often a provider data centre, and large webmail providers generally do not include the sender’s own IP in the headers.
Why does a hop show a negative delay?
The two servers’ clocks disagree. The analyzer shows the value so you can spot the wrong clock, but leaves it out of the total delay.
What does SCL mean in Microsoft headers?
The spam confidence level, from -1 to 9. Microsoft now decides spam or not with other signals, so the SFV and CAT fields in X-Forefront-Antispam-Report tell you more about what happened.