Protocol Threat Inspector

Email Header Analyzer — authentication, spoofing checks, and hop-by-hop delivery trace
DNS SOC diagnostics MODULE E
What is this? [legend]

Paste the raw headers of an email — everything from Received: down to Subject: — and this parses the authentication verdicts, the hop-by-hop delivery chain, and common spoofing indicators, entirely in your browser.

Nothing is uploaded anywhere. Parsing happens client-side; the header text never leaves your browser. This matters — email headers can contain sensitive routing and identity information.

Don't know where to find raw headers? In Gmail: open the email → ⋮ menu → "Show original". In Outlook: File → Properties → "Internet headers". Copy the whole block and paste it below.

Message Summary

— paste headers and analyze —

Authentication Results

— paste headers and analyze —

Sender Identity Check

— paste headers and analyze —

DKIM Signatures

— paste headers and analyze —

Received Chain (Delivery Hops)

— paste headers and analyze —

Other Headers of Interest

— paste headers and analyze —

All Parsed Headers

— paste headers and analyze —
"By way of deception, thou shalt make war"