In Gmail choose Show original; in Outlook View message source. Paste the headers below. Everything is analysed in your browser.
Gmail: open the message menu, Show original. Outlook: View message source. Paste everything above the first blank line.
From versus Reply-To versus Return-Path, the display name, the Authentication-Results line, the Received chain and the Message-ID.
Each finding says what was found and why it matters, with links to check any IP address in the path.
Scammers send from a convincing address but set Reply-To to a mailbox they control, so your answer reaches them. Legitimate senders rarely do this for personal mail.
They are checks your mail provider performs to verify that the sending server is allowed to use the domain (SPF), that the message was not altered (DKIM), and what to do when either fails (DMARC).
It can show whether the claimed sender passed authentication and where the message actually came from. Forged headers above the first trusted hop are possible, which is why the earliest Received lines matter.
Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.