Paste headers to analyze
SPF, DKIM, DMARC verdicts. Hop chain. Sender mismatch and spoofing detection.
—
Hops
—
Risk Flags
—
High
—
Transit
AUTH STATUS
SPF/DKIM/DMARC verdicts are read from the receiving server's Authentication-Results header, not re-verified against DNS. A forged Authentication-Results header is possible if the receiving MTA doesn't strip untrusted ones — treat these as strong signals, not ground truth.
ARC CHAIN
Origin IP
RISK FLAGS
HOP CHAIN
HEADER OVERVIEW
SENDER ANALYSIS
MICROSOFT 365 SIGNALS
SPAM FILTER
RAW HEADERS