Analyze Email Headers
Trace an email's real path and its SPF/DKIM/DMARC results to spot phishing.
The entire analysis runs in your browser. No header or file is ever sent to a server.
How do you tell if an email is phishing from its headers?
Paste the full email headers (or drop the .eml file) and Docuboxer reconstructs, in seconds, the real path the message took, the SPF/DKIM/DMARC results, and classic spoofing signals like a Reply-To pointing at a different domain or a display name imitating a brand. The whole analysis runs in your browser — nothing is ever uploaded — and it's free, with no signup and no usage limit. Unlike just glancing at the sender name your mail client shows, which an attacker fully controls, headers carry the technical details that are actually hard to fake completely: which servers the message touched, whether its domain passed authentication, and whether that authenticated domain actually matches the one the email claims to represent.
How to use Analyze Email Headers
- Open the suspicious email and copy its full headers: in Gmail, the three-dot menu (⋮) → "Show original"; in Outlook, File → Properties → "Internet headers". You can also download the message as an .eml file.
- Paste the text into the tool's box, or drag in the .eml file — Docuboxer only reads the headers from an .eml, the body is discarded and never parsed.
- Click "Analyze headers" and check the overall verdict: no risk signals, some signals worth checking, or phishing signals detected.
- Walk through the Received timeline to see which servers the email actually passed through, in what order, and how long each hop took.
- If the sender's domain fails SPF, DKIM, or DMARC, or From/Reply-To/Return-Path diverge, check that domain on /dns-check to see how it should be configured.
Common use cases
An urgent "your bank" email asks you to verify your account
Before clicking anything, check whether the sender's real domain matches the one the display name suggests — the single most common spoofing technique, and the first thing this analysis flags.
A coworker forwards a suspicious "CEO" email requesting a wire transfer
The Received chain and the Reply-To field usually give away the real origin of the message, even when the display name and signature look convincing.
IT or support needs to quickly confirm a user-reported phishing email
Instead of forwarding the full email content to an external service, headers are analyzed locally first — enough to decide whether to block a domain or alert the rest of the team.
One of your own legitimate emails starts landing in spam
Check whether your own SPF, DKIM, or DMARC are failing on the recipient's side — the same analysis works for debugging deliverability, not just catching attacks aimed at you.
Investigating a security incident after the fact
Reconstruct which servers a malicious email passed through and how long each hop took — useful detail when reporting it to the relevant hosting or mail provider.
Frequently asked questions
How do I get the full headers of an email in Gmail?
Open the email, click the three dots (⋮) in the top-right corner of the message, and choose "Show original". A new tab opens with the full header text — select all of it and paste it into this tool.
If an email passes SPF and DKIM, is it safe?
Not necessarily. Passing SPF/DKIM/DMARC only confirms the email authenticated correctly for the domain it claims to use — but many phishing attacks register their own lookalike domain (say "secure-bank-verify.com" instead of "securebank.com") and configure SPF and DKIM correctly right there. What actually matters is whether that authenticated domain matches the one you expect to see, not just whether the technical check passed.
What does it mean when Reply-To is different from From?
It means that even though the email claims to come from one sender, any reply gets routed to a completely different address. It's a very common phishing technique: the victim thinks they're replying to the original sender, but the message goes straight to the attacker.
Can I fully trust this tool to decide whether something is phishing?
Not as the sole proof. It's a technical aid that surfaces objective signals — domain mismatches, authentication failures, suspicious hops — but an email can fail every check and still be legitimate (misconfiguration), or pass every check and still be malicious (a freshly registered domain with its own valid SPF/DKIM). Use it alongside common sense, and when in doubt, contact the sender through another channel.
What is the Received chain and why does the order matter?
Every server an email passes through prepends its own Received header, so in the raw text they appear in reverse order — the most recent one on top. This tool reorders them chronologically and calculates the time between hops; a broken order or a huge gap between two hops can indicate hand-tampered headers.
Does Docuboxer upload my emails to a server to analyze them?
No. All parsing and analysis happens in JavaScript inside your browser. If you upload an .eml, its content is only read locally to separate the headers from the body — nothing ever leaves your device.