Orca Tech, Orca IT Solutions

Free Tool · Email Header Analyzer

Is that email real? The headers know

Every email carries hidden headers that record where it really came from and whether it passed authentication. Paste them in and get a plain-language verdict in seconds, analyzed entirely in your browser, before you click, reply or pay anything.

🔍 Instant Analysis 📧 SPF · DKIM · DMARC 🔒 Runs in Your Browser By Orca IT

Nothing you paste is sent anywhere · the analysis runs entirely on your device

What It Reads

What the hidden headers reveal

The pretty part of an email is easy to fake. The headers underneath are much harder to lie in. Here is what we decode.

SPF

Was the Server Allowed?

SPF shows whether the server that sent the message was authorized to send for that domain. Fail means it was not.

DKIM

Is the Signature Valid?

DKIM is a cryptographic signature. A pass proves the message left the real system unaltered.

DMARC

Is the From Address Real?

DMARC verifies the address you actually see. A fail here is the classic signature of a spoofed email.

Alignment

Display vs Reality

We compare the From address you see with the Return-Path it really used. Mismatches are a major tell.

Reply-To

Where Replies Really Go

Scammers show one address but route your reply to another. We flag it.

Path

The Delivery Trail

The Received chain records every server the message crossed, the forensic breadcrumbs.

When to Use It

Check before you act, not after

Thirty seconds with the headers beats a very expensive afternoon. Use this whenever something feels off.

The invoice with new bank details

Before any payment change, check the headers. Fake vendor emails fail authentication constantly.

The boss asking for a favor

Executive impersonation usually rides on failed DMARC or a free-mail Reply-To. The headers expose it instantly.

The password or account alert

Fake security alerts look perfect on the surface and fall apart in the headers.

The too-good offer or refund

Refund and prize emails from lookalike domains show their real sending path here.

When it passes, stay sharp

Clean authentication means the domain is real, not that the request is safe. Verify money asks by phone regardless.

When you are unsure, ask us

Forward the situation to us. Reading mail flow is daily work here, and fast answers prevent losses.

How It Works

From suspicious to certain

01

Grab the Headers

Gmail: three dots, Show original. Outlook: File, Properties, Internet headers.

02

Paste & Analyze

The verdict appears instantly, with each check explained in plain language.

03

Act Safely

Fail means delete and report. Unsure means verify by phone before doing anything.

04

Get Backup

Already clicked or paid? Send us the result and we move fast on containment.

Scammers fake the message. They can’t fake the math.

Authentication results do not lie. Thirty seconds here protects payments, passwords and payroll.

Get Expert Help

Why Orca

Why keep Orca behind this tool

A verdict is step one. When the email is hostile, or already clicked, the next steps are what we do all day.

01

Incident response, fast

Clicked, replied or paid? We contain it: passwords, sessions, mail rules and bank coordination, in the right order.

02

We stop the next one

Proper SPF, DKIM and DMARC on your own domain plus filtering keeps most of these out of inboxes entirely.

03

Training that sticks

Your team learns the tells with realistic examples, so the human filter improves too.

04

Plain-language always

You get answers in English, not acronyms, at 9 AM or mid-crisis.

05

20+ years of experience

Two decades of mail systems and the scams that abuse them.

06

Remote anywhere, onsite in Phoenix

Suspicious-email help is delivered remotely nationwide, with onsite support across the Phoenix area.

Questions

Header analysis, answered

How do I find an email's headers?

In Gmail, open the message, click the three dots and choose Show original. In Outlook, open the message, then File and Properties, and copy the Internet headers box. Paste everything into the analyzer.

Is it safe to paste headers here?

Yes. The analysis runs entirely in your browser, and nothing you paste is transmitted anywhere, including to us. Headers can contain your email address, which is another reason we built it this way.

The email failed. What do I do?

Do not click, reply or open attachments. Delete it, report it as phishing in your mail app, and warn anyone else who received it. If money or credentials were requested, verify with the real party by phone.

It passed everything. Is it definitely safe?

It means the sending domain is genuine, which rules out spoofing. It does not vouch for the request itself: compromised real accounts and lookalike domains with their own valid setup exist. Verify unusual money requests regardless.

What if I already clicked the link or replied?

Move quickly: change the affected password, sign out other sessions, enable MFA, and watch for password-reset emails. If anything financial was shared, call the bank now. Then contact us and we will check for deeper compromise.

Some checks say not found. What does that mean?

Some mail systems do not record full authentication results, and forwarded messages often lose them. Not found means unverified, so treat the message with the same caution as a warn.

Can you stop these emails from reaching my team at all?

Largely, yes. Correct SPF, DKIM and DMARC on your domain plus modern filtering blocks most spoofing and phishing before anyone sees it. That setup is one of our core services.

Suspicious Email?

Suspicious email? Let’s deal with it.

Send the analysis result and what happened, and we will confirm the verdict and next steps fast. Already clicked? Say so and we will prioritize you. Or just call.

(602) 677-0779

Suspicious email emergencies handled remotely anywhere · Onsite across the Phoenix area

Get help with this email

A few details and we’ll get right back to you to help.

Spam-protected with a quick CAPTCHA. We’ll only use your details to help with your request.