Paste the raw headers of a suspicious email and get a plain-English verdict — plus the evidence. We check SPF, DKIM, and the piece most tools skip: DMARC alignment (did anything actually pass for the sender’s own domain?), the delivery path, and impersonation tricks.
🔒 Runs entirely in your browser. Your headers — and any names or addresses in them — are parsed on your device. Nothing is sent to us, logged, or stored.
Where do I find the headers?
Gmail: open the message → ⋮ (More) → Show original → copy everything.
Outlook (desktop): open the message → File → Properties → copy the Internet headers box.
Outlook / Microsoft 365 (web): open the message → ⋯ (More actions) → View → View message details.
🛡️
Don’t want to check headers by hand?
The ThouShaltNotClick extension scores every message’s authentication and impersonation signals automatically, right inside Gmail and Outlook — with a trust badge before anyone clicks.
Header analysis reflects what the receiving servers recorded. Some fields (like Received hops) can be forged by an attacker, and a clean result is not a guarantee — when a message asks you to move money, change bank details, or share credentials, verify with the sender through a channel you already trust.