Browser-only utility

Email Header Analyzer, private by default

Review raw email headers for useful phishing and deliverability clues: from, reply-to, return-path, SPF, DKIM, DMARC, and received-chain signals.

Analyze raw email headers

Summary

Waiting for raw headers.

SPF

Missing

DKIM

Missing

DMARC

Missing

From

Not found

Reply-To

Not found

Return-Path

Not found

Subject

Not found

Date

Not found

Message-ID

Not found

Review clues
  • Paste raw headers with Name: Value lines to analyze them.

Received chain

0 delivery hops found.

No Received headers found yet.

Headers are parsed locally in your browser and are not uploaded to tempboxs.

How to use header analyzer safely

What raw email headers can tell you

Email headers are the technical envelope around a message. They include routing hops, sender fields, authentication results, mail client details, and identifiers used by mail servers.

Headers do not prove intent by themselves, but they can reveal useful warning signs when a message looks suspicious or when a test email is not arriving as expected.

Sender fields worth comparing

The visible From address is what most people notice first. Reply-To controls where replies go, and Return-Path is often used for bounces. In legitimate email these fields can differ, but unexpected mismatches deserve attention.

For example, a message that claims to be from a bank but sends replies to a free webmail account is a stronger phishing signal than the display name alone.

  • From: the visible sender shown by most email clients
  • Reply-To: where your reply may be sent
  • Return-Path: the bounce address used by mail systems
  • Authentication-Results: SPF, DKIM, and DMARC outcomes when a receiving server adds them

Limits of header analysis

A header analyzer is a review tool, not a guarantee. Forwarding, mailing lists, help desks, and CRM systems can create complicated but legitimate headers.

Use header analysis alongside normal safety habits: verify the domain, avoid unexpected attachments, do not paste one-time codes into surprise login pages, and use a password manager to catch fake domains.

Why people use this tool

Headers are parsed locally in your browser. tempboxs does not receive pasted email headers or message metadata.

Spot sender mismatches

Compare From, Reply-To, and Return-Path fields to find obvious identity mismatches.

Review auth clues

Extract SPF, DKIM, and DMARC mentions from Authentication-Results when they are present.

Understand delivery hops

Count Received headers and inspect the first few hops without uploading message metadata.

Guides from the blog

Learn more about privacy, tracking, passwords, and safer signups.

AdSense Checklist

Review content quality, policy pages, ad placement, crawlability, and technical files before AdSense checks.

ads.txt Checker

Generate a Google AdSense ads.txt line and check pasted authorized-seller records locally before publishing.

UUID Generator

Generate random UUID v4 identifiers in your browser, copy one value, or create a small batch for testing.

Timestamp Converter

Convert Unix timestamps, milliseconds, ISO dates, and local-readable times locally in your browser.

Meta Analyzer

Paste page HTML to inspect title tags, meta descriptions, canonical URLs, robots directives, Open Graph tags, and JSON-LD locally in your browser.

Schema Generator

Generate JSON-LD schema markup for articles, FAQ pages, web pages, and browser tools locally before publishing.

OG Preview

Draft Open Graph and Twitter card preview tags locally for articles, tools, landing pages, and social shares.

llms.txt Generator

Generate an llms.txt draft for AI discovery with public pages, useful tools, safety notes, and crawling guidance.

Sitemap Generator

Generate sitemap XML from public URLs and check duplicate or invalid entries locally before publishing.

Robots Tester

Paste robots.txt rules to test whether a URL path appears allowed or blocked for Googlebot, Bingbot, or another crawler locally in your browser.

JWT Decoder

Decode JWT headers and payloads locally in your browser, inspect claims, and learn what still needs verification.

Strength Checker

Check password length, character variety, common patterns, and estimated guess resistance locally in your browser.

Pixel Checker

Paste email HTML to find likely tracking pixels, remote images, and marketing links locally in your browser.

YAML to JSON

Convert common YAML snippets into formatted JSON locally in your browser for configs, docs, and API examples.

User Agent Parser

Parse browser, operating system, device, engine, and bot hints from user agent strings locally in your browser.

URL Parser

Parse a URL into protocol, origin, hostname, port, path, query parameters, hash, and decoded components locally in your browser.

URL Encoder

Encode URL text into percent-escaped values or decode encoded URLs locally in your browser.

URL Cleaner

Clean tracking parameters from links, decode common redirect URLs, and inspect domains locally in your browser.

DNS Records

Look up common DNS record types, purposes, examples, and setup notes locally in your browser.

UTM Builder

Build campaign URLs with UTM source, medium, campaign, term, and content parameters locally in your browser.

JSON Formatter

Format, minify, and validate JSON locally in your browser with clear error feedback.

HTML Entities

Encode HTML-sensitive characters or decode named and numeric entities locally in your browser for docs, blog posts, comments, and support replies.

Regex Tester

Test JavaScript regular expressions, flags, matches, indexes, and capture groups locally in your browser.

MIME Types

Look up common file extensions, MIME types, categories, and delivery notes locally in your browser.

Markdown Previewer

Preview Markdown headings, lists, links, inline styles, and code blocks locally in your browser before publishing docs or guides.

Privacy Checklist

Generate a browser-only privacy checklist for signups, support tickets, link sharing, and publishing workflows.

Word Counter

Count words, characters, sentences, paragraphs, reading time, speaking time, and repeated terms locally in your browser.

Contrast Checker

Check foreground and background hex colors against common WCAG contrast thresholds locally in your browser.

Cron Explainer

Explain five-field cron expressions locally in your browser with readable field meanings and schedule warnings.

CSS Units

Convert CSS px, rem, em, and percent values locally in your browser with adjustable root and parent font sizes.

CSV to JSON

Convert CSV or tabular spreadsheet exports into formatted JSON locally in your browser with header and delimiter controls.

Case Converter

Convert text into lowercase, uppercase, title case, sentence case, slug, snake_case, kebab-case, camelCase, and PascalCase locally in your browser.

HTTP Status Codes

Look up common HTTP status codes, meanings, categories, and troubleshooting notes locally in your browser.

Base64 Converter

Encode plain text to Base64 or decode Base64 back to UTF-8 text locally in your browser.

Hash Generator

Generate SHA-256, SHA-384, and SHA-512 hashes for text or local files without uploading them.

FAQ

No. The analyzer runs locally in your browser and does not send pasted headers to tempboxs.

No. It highlights technical clues, but phishing decisions need context, domain checks, message content review, and safe handling of links or attachments.

Not every copied header includes Authentication-Results. Some email clients hide technical headers unless you choose an option such as Show original or View source.

Yes. Newsletters, support desks, and mailing lists often use different bounce and reply domains. Treat mismatches as a clue to investigate, not automatic proof of abuse.