Skip to content
Klarinbox

Read the headers of an email

The headers of a message say which servers it went through, at what time, and what the receiving server checked. Drop the message: they are put back in order and explained line by line.

Or drop an .eml or a .msg here. Nothing is uploaded: the files stay in this tab.

When to use it

A message seems to come from your bank, a supplier or a colleague, and something feels off. Or a message arrived hours late, and you want to know where it waited.

The headers answer part of that, but they read from bottom to top, with times in several time zones and lines hundreds of characters long.

What this tool does

What it does not do: Nothing is checked live: the DKIM signature is not recomputed and no DNS query is made, since it would leave the tab. The results shown are those the receiving server recorded. Klarinbox says what it observes; it never says a message is fake or authentic.

What it reads

No file is uploaded: the message is read by your browser, in this tab, and the page is not allowed to open a connection to any other site.

Frequently asked questions

How do I see the headers of an email?
Save the message as a file (Gmail: "Download message" gives an .eml; Outlook: dragging the message to the desktop gives a .msg) and drop it here.
Is a message that fails SPF fraudulent?
Not necessarily. Automatic forwarding, a mailing list or a badly declared sending service make SPF fail on legitimate messages. It is a clue to weigh against the others, not a verdict.
Why is the DKIM signature not verified here?
It would require asking DNS for the sender's public key, that is, leaving the tab. Nothing leaves it: the result shown is the one the receiving server recorded when the message arrived.

Other tools