go-supertools
Security & Privacy Tools

Email Header Decoder

Parse raw email headers into key fields and a list of Received hops.

Runs in your browser Your input never leaves your device.

0 characters | 0 words
—

About this tool

Reads raw email headers and pulls out the parts people usually need. It shows From, To, Subject, Date, Message-ID, Return-Path Reply-To, Cc and a few authentication fields (X-Originating-IP, Authentication-Results, Received-SPF) when present, then lists each Received hop with the sending and receiving server names. Folded lines (continuations that start with a space) are joined correctly. In most mail clients you can copy the raw headers through a menu such as Show original or View source. The tool only parses text: it does not verify SPF, DKIM or DMARC. Encoded-word values such as =?UTF-8?B?...?= or =?ISO-8859-1?Q?...?= (RFC 2047) are decoded to readable text. Other values are displayed as they appear, so a forged header can look just like a real one. Parsing runs in your browser.

How to use it

  1. Open the message in your mail client and copy its full raw headers.
  2. Paste them into the box.
  3. Read the main fields and the numbered Received hops; hop 1 is the oldest, closest to the sender.
  4. Compare the first hop and Return-Path with the claimed sender if you suspect spoofing.

Example

Shortened sample; real headers usually have several hops.

Input
Received: from mail.example.org (mx1 [203.0.113.5])
 by mx.example.com with ESMTP; Mon, 1 Jan 2024 10:00:00 +0000
From: Alice <alice@example.org>
Subject: Hello
Result
From: Alice <alice@example.org>
Subject: Hello

Received hops: 1
  1. mail.example.org → mx.example.com

Common problems

No hops or fields are shown
Paste only the header block, starting from the first header line. Each line must look like Name: value.
Sender looks trustworthy but the mail is suspicious
From and Reply-To are easy to forge. This tool does not check authentication results, so look at the Authentication-Results header in your mail client too.
Subject appears as =?UTF-8?B?...
Encoded-word text is shown as is and not decoded.