Disposable email Tools
Updated 6 October 2026
An email can show any sender name it likes. Its headers, however, keep a record of where it really came from. Paste them below: the analysis runs in your browser and nothing is sent anywhere.
| Email service | Path |
|---|---|
| Gmail | Open the message › ⋮ menu › "Show original" › copy the whole top part |
| Outlook (web) | Open the message › ⋯ › "View" › "View message details" |
| Apple Mail | View › Message › "All Headers" |
| Thunderbird | View › "Message Source" (Ctrl+U) |
| Yahoo Mail | ⋯ › "View raw message" |
Copy the whole block, from the first "Received:" down to the blank line that separates the headers from the text of the message.
A genuine message from a large company usually shows three "pass" results and consistent domains. A phishing message sometimes passes SPF, but for its own sending domain, not for the bank it imitates: then DMARC fails and gives it away.
Be careful: only the top part of the headers, added by your own email service, can be trusted. The lines at the bottom may have been written by the sender.
No. The analysis is done by your browser, on your device. Nothing is sent to Boxo or to any other service.
These results are added by the email service that receives the message. If you copy the headers from somewhere else, or if the provider does not add them, they are missing.
No: it only proves that the displayed domain really sent the message. A scammer can use a look-alike domain of their own with perfect authentication. Always check the domain itself.