Disposable email Tools

Email header analyzer

Updated 6 October 2026

An email can show any sender name it likes. Its headers, however, keep a record of where it really came from. Paste them below: the analysis runs in your browser and nothing is sent anywhere.

Where to find the headers

Email servicePath
GmailOpen the message › ⋮ menu › "Show original" › copy the whole top part
Outlook (web)Open the message › ⋯ › "View" › "View message details"
Apple MailView › Message › "All Headers"
ThunderbirdView › "Message Source" (Ctrl+U)
Yahoo Mail⋯ › "View raw message"

Copy the whole block, from the first "Received:" down to the blank line that separates the headers from the text of the message.

What the tool checks

How to read the result

A genuine message from a large company usually shows three "pass" results and consistent domains. A phishing message sometimes passes SPF, but for its own sending domain, not for the bank it imitates: then DMARC fails and gives it away.

Be careful: only the top part of the headers, added by your own email service, can be trusted. The lines at the bottom may have been written by the sender.

Get a disposable address

Frequently asked questions

Are the headers I paste sent anywhere?

No. The analysis is done by your browser, on your device. Nothing is sent to Boxo or to any other service.

Why does the tool show "missing" for SPF, DKIM or DMARC?

These results are added by the email service that receives the message. If you copy the headers from somewhere else, or if the provider does not add them, they are missing.

Is a message with three "pass" results necessarily safe?

No: it only proves that the displayed domain really sent the message. A scammer can use a look-alike domain of their own with perfect authentication. Always check the domain itself.

Read next