The From address on an email can be forged. Here's how to read the raw headers to prove whether an email is really from who it claims — and where it actually came from.
The 'From' address on an email is just text — anyone can type whatever they want there. The proof of who really sent a message lives in its raw headers: the authentication results (SPF, DKIM, DMARC) and the chain of servers it passed through. Analyzing those tells you whether an email is authentic or forged, and often reveals the attacker's real infrastructure.
—Red flags before you even open the headers
- Urgency or threats ('your account will be closed', 'verify now').
- A link that doesn't match the real company's domain (hover to check).
- Requests for passwords, codes, payment, or your crypto recovery phrase.
- Slightly-off sender domains (paypa1.com, ledger-support.co).
—Analyze the raw headers
Paste the full source of the email (in Gmail: ⋮ → 'Show original'). The analyzer checks SPF/DKIM/DMARC, detects locally-injected/spoofed senders, and traces the true origin.
Use the toolAnalyze email headersEmail Header Analyzer→You can also check the sender's address itself for disposable/temp-mail domains and fraud history, and scan any domain or link it contains.
Use the toolCheck an email addressEmail Fraud Checker→Never click to 'verify'
Don't enter credentials or codes from a link in an email. Go to the site directly by typing its address yourself. If it's real, you'll see the same notice when you log in normally.
Get a step-by-step action plan tailored to your exact situation.
Open the guided help wizard →