Analyze email headers
Paste the full headers of a message to see every server it passed through, where it waited, and whether SPF, DKIM and DMARC passed at the receiving end. Read in your browser, in plain words.
How to read email headers
Headers are the envelope and the postmarks together. The ones you wrote are at the bottom: From, To, Subject, Date. Above them, every server that handled the message stamped a Received line on top, so the block reads newest first. The receiving mailbox adds the most useful line of all, Authentication-Results, where it records whether SPF, DKIM and DMARC passed from its point of view. That one line is the answer to most "why did this go to spam" questions, and it is the first thing this tool pulls out.
Everything else is supporting detail. DKIM-Signature tells you which domain signed the message and under which selector. Return-Path is where bounces go, and it is the address SPF is actually checked against, which is why it can differ from the From line. X- headers are notes servers leave for themselves, including spam scores.
Why did my password reset email go to spam?
Pull the headers from the copy that landed in spam, not from your outbox. If the Authentication-Results line shows dkim=pass and dmarc=pass, the message was authenticated and the filter judged it on reputation or content: a new sending domain, a shared IP with a bad neighbour, a subject line that trips a rule, or simply that recipients never engage. If it shows spf=pass but dmarc=fail, your sending service passes for its own domain while your From address is yours, and the two do not align. Sign with DKIM under your domain, or set up the custom bounce domain the service offers.
A missing Authentication-Results line means you are looking at the wrong copy. Gmail's "Show original", Outlook's "View message source" and Apple Mail's "All Headers" each give the received copy with the verdicts in it.
Where did the delay happen?
Each Received line carries a timestamp, so the gap between two of them is the time the message sat on the earlier server. The hop table above marks the largest gap. A wait of several minutes at the first hop after your server usually means the receiver greylisted you: it refused the first attempt and your server retried. A long wait before a scanning gateway means the gateway held the message for inspection. Gaps of a few seconds either way can be clock drift between servers and mean nothing.
If the message never arrived at all there are no headers to read, and the useful evidence is on the sending side: the bounce message, with its SMTP code, which the SMTP error code library explains one code at a time.
Mail that passes on the first try.
Faivelo signs every message with DKIM under your domain, keeps SPF and DMARC aligned, and shows delivery and bounce events per message. No more reading headers to find out what happened.
Free 14-day trial. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.
- SMTP error codesWhat each bounce code means, which provider sends it and how to fix it, one page per code.