1. What does this analyzer measure?
It measures authentication status, sender alignment, route visibility, and notable anomalies in raw email headers. The score helps prioritize suspicious messages for manual review.
Decode sender paths, trust checks, and relay anomalies. Turn raw headers into actionable security insights. Review results faster with clean scoring, exports, and guidance.
Paste the original raw header block from your mail client or gateway.
| Scenario | SPF | DKIM | DMARC | Alignment | Hops | Risk Score | Verdict |
|---|---|---|---|---|---|---|---|
| Corporate newsletter from aligned infrastructure | PASS | PASS | PASS | Strong | 4 | 9 | Low |
| Marketing relay with missing DKIM and extra hops | PASS | NOT FOUND | NONE | Partial | 8 | 44 | Elevated |
| Brand spoof with auth failures and domain mismatch | FAIL | FAIL | FAIL | Weak | 2 | 86 | Critical |
Auth points come from SPF, DKIM, and DMARC outcomes. Alignment points reflect sender-domain consistency across From, Reply-To, Return-Path, and Message-ID. Routing points measure relay-path complexity and missing transport evidence. Anomaly points cover missing headers, private or reserved IP exposure, and weak observability signals.
The calculator converts the weighted total into a 0 to 100 risk score. Lower scores suggest healthier trust signals. Higher scores indicate stronger spoofing, routing, or authenticity concerns that deserve manual review.
It measures authentication status, sender alignment, route visibility, and notable anomalies in raw email headers. The score helps prioritize suspicious messages for manual review.
No. A low score means the supplied headers look more consistent. Content, links, attachments, and user context can still make a message risky.
Forwarding services, broken sender policies, legacy relays, or missing gateway headers can raise the score. Always combine header analysis with delivery context.
Domain alignment compares the visible sender with Reply-To, Return-Path, and Message-ID domains. Strong alignment generally improves authenticity confidence.
Private or reserved IPs may appear in internal relays or redacted traces. They are not automatically malicious, but they reduce route transparency.
Yes. The calculator lets you change authentication, alignment, routing, and anomaly weights so the scoring fits your environment or playbook.
No. It is a decision-support tool. Investigators should still validate content, infrastructure reputation, user reports, and mailbox telemetry.
Paste the original raw headers, including Received, Authentication-Results, Received-SPF, From, Reply-To, Return-Path, Date, and Message-ID whenever available.
Important Note: All the Calculators listed in this site are for educational purpose only and we do not guarentee the accuracy of results. Please do consult with other sources as well.