Message provenance

Email Header Forensics

Decode authentication results, Received hops, identity changes and delivery delays from a raw header or .eml file.

email header analyzerreceived header analyzeremail trace analyzereml analyzer
Analyze message provenanceWhen you choose an .eml file, the message body is removed in your browser before analysis.
Authentication · identity · Received chain · latency

What this analysis does

The analysis reconstructs the visible transit path, summarizes SPF/DKIM/DMARC/ARC results already stamped by receiving systems, identifies identity fields and computes hop timing when timestamps are available.

How to use the result

Use real evidence

Paste the exact domain, header, message or configuration. The result is only as useful as the evidence supplied.

Review the findings

Mailybox separates observations from inferred causes so you can see what is known and what still needs verification.

Retest after changes

Email authentication and routing are stateful. Re-run the analysis after publishing a fix.

Interpretation matters

Email systems combine DNS, message-level evidence, provider policy and intermediate infrastructure. A single passing check is not proof that every message will deliver, and a single warning is not proof that a domain is misconfigured. Mailybox is designed to expose the evidence and the relationship between signals so the next action is clear.