Was the Server Allowed?
SPF shows whether the server that sent the message was authorized to send for that domain. Fail means it was not.
Free Tool · Email Header Analyzer
Every email carries hidden headers that record where it really came from and whether it passed authentication. Paste them in and get a plain-language verdict in seconds, analyzed entirely in your browser, before you click, reply or pay anything.
Nothing you paste is sent anywhere · the analysis runs entirely on your device
What It Reads
The pretty part of an email is easy to fake. The headers underneath are much harder to lie in. Here is what we decode.
SPF shows whether the server that sent the message was authorized to send for that domain. Fail means it was not.
DKIM is a cryptographic signature. A pass proves the message left the real system unaltered.
DMARC verifies the address you actually see. A fail here is the classic signature of a spoofed email.
We compare the From address you see with the Return-Path it really used. Mismatches are a major tell.
Scammers show one address but route your reply to another. We flag it.
The Received chain records every server the message crossed, the forensic breadcrumbs.
When to Use It
Thirty seconds with the headers beats a very expensive afternoon. Use this whenever something feels off.
Before any payment change, check the headers. Fake vendor emails fail authentication constantly.
Executive impersonation usually rides on failed DMARC or a free-mail Reply-To. The headers expose it instantly.
Fake security alerts look perfect on the surface and fall apart in the headers.
Refund and prize emails from lookalike domains show their real sending path here.
Clean authentication means the domain is real, not that the request is safe. Verify money asks by phone regardless.
Forward the situation to us. Reading mail flow is daily work here, and fast answers prevent losses.
How It Works
Gmail: three dots, Show original. Outlook: File, Properties, Internet headers.
The verdict appears instantly, with each check explained in plain language.
Fail means delete and report. Unsure means verify by phone before doing anything.
Already clicked or paid? Send us the result and we move fast on containment.
Authentication results do not lie. Thirty seconds here protects payments, passwords and payroll.
Why Orca
A verdict is step one. When the email is hostile, or already clicked, the next steps are what we do all day.
Clicked, replied or paid? We contain it: passwords, sessions, mail rules and bank coordination, in the right order.
Proper SPF, DKIM and DMARC on your own domain plus filtering keeps most of these out of inboxes entirely.
Your team learns the tells with realistic examples, so the human filter improves too.
You get answers in English, not acronyms, at 9 AM or mid-crisis.
Two decades of mail systems and the scams that abuse them.
Suspicious-email help is delivered remotely nationwide, with onsite support across the Phoenix area.
Questions
In Gmail, open the message, click the three dots and choose Show original. In Outlook, open the message, then File and Properties, and copy the Internet headers box. Paste everything into the analyzer.
Yes. The analysis runs entirely in your browser, and nothing you paste is transmitted anywhere, including to us. Headers can contain your email address, which is another reason we built it this way.
Do not click, reply or open attachments. Delete it, report it as phishing in your mail app, and warn anyone else who received it. If money or credentials were requested, verify with the real party by phone.
It means the sending domain is genuine, which rules out spoofing. It does not vouch for the request itself: compromised real accounts and lookalike domains with their own valid setup exist. Verify unusual money requests regardless.
Move quickly: change the affected password, sign out other sessions, enable MFA, and watch for password-reset emails. If anything financial was shared, call the bank now. Then contact us and we will check for deeper compromise.
Some mail systems do not record full authentication results, and forwarded messages often lose them. Not found means unverified, so treat the message with the same caution as a warn.
Largely, yes. Correct SPF, DKIM and DMARC on your domain plus modern filtering blocks most spoofing and phishing before anyone sees it. That setup is one of our core services.
Free Tools
No email walls, no tricks. Useful tools that run right in your browser.
Suspicious Email?
Send the analysis result and what happened, and we will confirm the verdict and next steps fast. Already clicked? Say so and we will prioritize you. Or just call.
(602) 677-0779Suspicious email emergencies handled remotely anywhere · Onsite across the Phoenix area
A few details and we’ll get right back to you to help.