EMAIL FORENSICS / LOCAL ANALYSIS
Follow the message.
Question the identity.
Turn raw email headers into an authentication summary, identity-alignment checks and a readable delivery route.
What this tool does
It interprets evidence already present in the headers. It does not independently query DNS, verify a DKIM signature or prove that a sender is trustworthy.
01 / INPUT
Paste raw email headers
03
IDENTITY
Who the message claims to be
04
ROUTE
Delivery path
Received headers are shown from the earliest observed hop to the final receiving system. Header order can be forged before a trusted boundary.
05
EVIDENCE
Findings and next actions
INTERPRETATION MODEL v1.0
Evidence before verdict
- 1Read reported authenticationInterpret the receiving system’s SPF, DKIM, DMARC and ARC results.
- 2Compare identitiesCheck visible From, Return-Path, Reply-To, DKIM signing domain and Message-ID.
- 3Trace transportReconstruct the Received chain and highlight malformed or missing route evidence.
- 4Explain uncertaintyMissing headers remain unknown; they are never converted into a pass or fail.