Paste the headers from any suspicious email. In seconds you get a forensic breakdown of SPF, DKIM and DMARC, the full route the message travelled, and a plain-English verdict on whether the sender is genuine or forged.
10 free checks every month. No credit card required.
Outlook: File → Properties → Internet headers. Gmail: ⋮ → Show original. Apple Mail: View → Message → All Headers.
Everything is parsed locally on our server, scored against 30+ forensic checks, and returned instantly. Nothing is sent to a third party.
A plain-English answer, a trust score, and a ranked list of exactly what is wrong — not a wall of raw headers.
Authentication proves where a message came from — never what the sender intends. So we score origin and risk on separate axes, and tell you which one is the problem.
Full parse of Authentication-Results, Received-SPF and every DKIM signature, including which domain actually signed.
Whether the visible From: address genuinely matches the cryptographically authenticated domain.
Edit-distance matching against 35 commonly impersonated brands, plus punycode/homograph detection.
Catches “PayPal Support <random@gmail.com>” and addresses hidden inside the display name.
The single most common trick in invoice fraud and business email compromise.
Rebuilds every hop, checks timestamps run forward, and flags injected or forged Received headers.
Fingerprints SES, SendGrid, Mailgun, Postmark, Mailchimp, Resend, Microsoft 365, Google Workspace and more.
Reads the spam, phishing and malware verdicts the receiving mail system already recorded.
Whether the message actually crossed the internet encrypted, or in the clear.
Every check you run is saved to your account, forever.
For occasional checks.
For teams triaging suspicious mail every day.
Create a free account and check your first email in under a minute.
Create free account