Free tool • Stays in your browser

Is this email legit?
Read the headers

Paste the technical headers from a suspicious message. We’ll translate SPF, DKIM, DMARC, Reply-To tricks, and other signals into plain English.

Analysis runs locally in your browser. We don’t upload your headers to Network26.

SPF DKIM DMARC Reply-To
Plain English. No signup.
HOW TO GET HEADERS

Copy the technical view, not the body

You need the hidden routing and authentication lines. Here’s the short path in common apps.

1

Outlook (Microsoft 365)

Open the message → or File → ViewView message details / Internet headers. Copy the full block.

2

Gmail

Open the message → Show original. Copy everything, or at least from the top through the authentication lines.

3

Apple Mail

View → MessageAll Headers (or Raw Source, depending on version). Copy the header section above the body.

WHAT WE LOOK FOR

Signals that matter for SMBs

Authentication-Results (SPF / DKIM / DMARC)

Your provider’s verdict on whether the sender’s domain checks out. A DMARC pass is a strong sign the From: domain is aligned. A fail is a reason to slow down.

From vs Reply-To

Looks like your vendor or CEO, but replies go to a totally different address? That’s a classic invoice / wire-fraud pattern.

Display-name tricks

The friendly name in your inbox can lie. We flag when the display name embeds a different email than the real From: address.

Also try our DMARC domain checker and spoof preview.

Suspicious mail still landing?

We help Puget Sound teams lock down email authentication, reduce spoof risk, and get same-day help when something looks wrong.