Paste the technical headers from a suspicious message. We’ll translate SPF, DKIM, DMARC, Reply-To tricks, and other signals into plain English.
Analysis runs locally in your browser. We don’t upload your headers to Network26.
You need the hidden routing and authentication lines. Here’s the short path in common apps.
Open the message → ⋯ or File → View → View message details / Internet headers. Copy the full block.
Open the message → ⋮ → Show original. Copy everything, or at least from the top through the authentication lines.
View → Message → All Headers (or Raw Source, depending on version). Copy the header section above the body.
Your provider’s verdict on whether the sender’s domain checks out. A DMARC pass is a strong sign the From: domain is aligned. A fail is a reason to slow down.
Looks like your vendor or CEO, but replies go to a totally different address? That’s a classic invoice / wire-fraud pattern.
The friendly name in your inbox can lie. We flag when the display name embeds a different email than the real From: address.
Also try our DMARC domain checker and spoof preview.
We help Puget Sound teams lock down email authentication, reduce spoof risk, and get same-day help when something looks wrong.