Skip to content

Email Header Analyzer guide

Tool guide. Updated .

How to copy full email headers, what the XGM Email Header Analyzer shows about delivery hops, delays and authentication, and how to spot spoofing signs.

What email headers contain

Every mail server that handles a message adds a Received header at the top, recording where it got the message from, its own name and a timestamp. The receiving mail server also adds Authentication-Results, which records the outcome of SPF, DKIM and DMARC checks. Together they are the closest thing to a delivery receipt email has.

Headers added before your provider's servers are written by other systems and can be forged, while headers added by your own provider are trustworthy. That is why analysis usually starts at the top, with the hops your provider added, and works down.

How Received headers stack upEach server adds a Received header above the existing ones, so the bottom header is the first hop and the top header is the last; the analyzer reverses them into delivery order.Sender's mail client submits the messageReceived: from laptop by smtp.example.com;timestamp 1Sending server relays to the recipient'sMXReceived: from smtp.example.com bymx.example.net; timestamp 2Receiving server checks authenticationAuthentication-Results: spf=pass dkim=passdmarc=passInternal delivery to the mailboxReceived: from mx.example.net bystore.example.net; timestamp 3Analyzer viewHops in order 1 → 3 with the delay betweeneach
Each server adds a Received header above the existing ones, so the bottom header is the first hop and the top header is the last; the analyzer reverses them into delivery order.

Copying the full headers

Mail clients hide headers by default, so you need the "original" or "source" view. Copy everything from the first line down to the start of the message body; the analyzer ignores the body if you include it.

Where to find the original message
ClientMenu
Gmail (web)Open the message, three-dot menu → Show original
Outlook (web and new Outlook)Open the message, three-dot menu → View → View message source (or message details)
Apple MailView → Message → All Headers, or Raw Source
ThunderbirdView → Message Source

Menu names change between versions, but every major client has an option labelled original, source or headers. Forwarding a message does not preserve its original headers; forward it as an attachment if someone else needs to analyse it.

How to use the analyzer

  1. Open the Email Header Analyzer and paste the full headers.
  2. Read the summary: From, Return-Path, Reply-To, Subject, Date and Message-ID.
  3. Check the SPF, DKIM and DMARC results taken from Authentication-Results.
  4. Follow the hop timeline to see where time was spent, and read the warnings.
  5. Export the result as JSON to get every parsed header, including the full Authentication-Results line with the DKIM selector (header.s) and signing domain (header.d).

Stays in your browser

Parsing happens locally in the page. Headers can contain internal server names, IP addresses and addresses of recipients, so this is a safer place to paste them than a tool that uploads them.

Reading authentication results

A typical Authentication-Results header
Authentication-Results: mx.example.net;
       dkim=pass header.i=@example.com header.s=s2026a header.b=AbCdEf12;
       spf=pass (example.net: domain of bounce@example.com designates 192.0.2.25 as permitted sender) smtp.mailfrom=bounce@example.com;
       dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=example.com
Result values
ResultMeaning
passThe check succeeded
failThe check failed: not authorised (SPF), bad signature (DKIM), or not aligned (DMARC)
softfailSPF ~all matched: not authorised, treat with suspicion
neutral / noneNo usable statement, or no record published
temperrorA temporary DNS problem prevented the check
permerrorThe record is broken, such as an SPF record over the lookup limit

DMARC is the result that ties the others to the visible From address. A message can show spf=pass for a sending service's bounce domain and still fail DMARC, because that domain is not aligned. The DMARC guide explains alignment, and the DKIM guide covers signature failures.

What the warnings mean

Analyzer warnings
WarningWhy it matters
DMARC failedThe From domain was not authenticated by an aligned SPF or DKIM result; the message may be spoofed.
SPF fail or softfailThe sending server is not authorised by the envelope domain.
DKIM failedThe signature does not match; the message may have been modified in transit.
Envelope sender differs from the From domainCommon for mailing services, but also for spoofing; check DMARC.
Replies go to a different domainA Reply-To on another domain is a common phishing pattern.
Hops with earlier timestampsA server clock is wrong, or headers were forged.
No headers foundPaste the full original message source, headers first.

When all three authentication results pass and the From domain is one you expect, the message almost certainly came from that domain's mail system. When DMARC fails for a domain that publishes p=reject, most large providers would have rejected it, so finding it in an inbox is itself worth reporting.

Warnings are signals, not verdicts. Newsletter platforms routinely use their own envelope sender, and support desks set Reply-To addresses on purpose. Combine the warnings with the authentication results and the context of the message.

Finding delivery delays

The analyzer calculates the time between consecutive hops and the total from the first to the last. A delay of seconds is normal, a few minutes can come from spam filtering or queueing, and hours usually mean a server retried after a temporary failure. The hop where the delay appears points to the system responsible.

Common delay patterns
Where the delay isLikely cause
Before the first hop of the sending providerMessage queued in the sender's client or application
Between the sending server and the recipient's MXReceiver deferred the message (greylisting, rate limits, temporary errors)
Inside the recipient's systemContent scanning, sandboxing of attachments, or internal queues
Negative delayClock differences between servers or forged headers

FAQ

Are my headers uploaded?

No. The analyzer runs in your browser, and the pasted text is not sent to XGM.

Which Received header is the first hop?

The bottom one. Each server adds its header on top, so the analyzer reverses the list to show delivery order.

Can Received headers be faked?

Headers added before the message reached your provider can be forged by the sender. Headers added by your own provider's servers are reliable.

Why does SPF pass but DMARC fail?

SPF passed for the envelope sender's domain, which is not aligned with the From domain. DMARC needs an aligned SPF or DKIM pass.

How can I find the DKIM selector?

Look for header.s= in Authentication-Results, or s= in the DKIM-Signature header. Both are in the pasted source and in the analyzer's JSON export.

Why are there more hops than servers I know about?

Large providers pass messages through several internal systems for filtering, scanning and storage, and each adds a Received header. Only the hops between organisations usually matter for troubleshooting.

What does the with field in a hop mean?

It names the protocol used for that hop, such as ESMTPS (SMTP with TLS) or ESMTPSA (with TLS and authentication). Plain SMTP or ESMTP means that hop was not encrypted.

Why is authentication shown as not found?

The headers do not contain an Authentication-Results line with that method. Some clients strip it, or the paste started after it; copy the full original source.

Can I tell where the sender is located?

Only roughly. The first external hop often shows the sending server's IP, which you can look up with IP Intelligence, but that is usually a mail provider, not the person.

What should I do with a phishing message?

Report it through your mail client's phishing button or to your IT team. Header analysis helps confirm spoofing, but do not click links or reply.

Sources