Free Email Investigation Tool

Email Header Analyzer: Decode SPF, DKIM, DMARC & Sender Mismatches

The message body is what an attacker wants you to look at. The headers are where they usually slip up. Upload or paste an email into TrustCan and it extracts the sender details and authentication results so you can see what's really going on underneath.

Scan a Link or Email — Free →

The headers TrustCan extracts

  • From, Reply-To, and Return-Path — three different addresses that should usually line up, and often don't in a spoofed message.
  • Message-ID — a unique identifier for the message, useful when comparing against other suspicious emails.
  • Authentication-Results — the SPF, DKIM, and DMARC verdicts the receiving mail server already calculated.

Reply-To mismatch: a classic BEC tell

If the From address says your CEO but the Reply-To quietly points to a free webmail account or a lookalike domain, that's one of the strongest signs of business email compromise — the attacker wants your reply, not the CEO's. TrustCan flags this mismatch automatically.

Authentication passing doesn't mean safe

This is worth repeating: a message can pass SPF, DKIM, and DMARC and still be actively malicious — for example, if the sender's real account was compromised and is being used to send phishing links to their own contacts. Authentication tells you the message is genuinely from that account. It does not tell you that account, or its content, can be trusted right now.

Frequently asked questions

How do I get the raw headers from an email?
In Gmail, open the message, click the three-dot menu, and choose 'Download message' to get an .eml file. In desktop Outlook, use File > Save As to get a .msg file. In Outlook on the web, use the download option from the message menu. Upload that file directly, or open it in a text editor and paste the header section.
What's the difference between SPF, DKIM, and DMARC?
SPF checks whether the sending server is authorized to send mail for that domain. DKIM checks a cryptographic signature proving the message wasn't altered in transit. DMARC ties the two together and tells receiving servers what to do if they fail. All three describe sender authentication — none of them evaluate whether the content itself is malicious.
Why does a Reply-To mismatch matter so much?
Most people never notice the Reply-To header — they just hit reply. Attackers exploit this by sending from a spoofed or lookalike From address while quietly routing replies to an address they control, so your response goes straight to them, not the real sender.
If SPF, DKIM, and DMARC all pass, is the email safe?
No. Passing authentication only proves the message really came from where it claims to have come from — it says nothing about whether that sender's account has been compromised or whether the content is malicious. Authenticated senders can and do send phishing content, especially from hijacked accounts.
Worried someone already clicked, downloaded a file, entered a password, or sent money? Contact Phenicie Business Management now at (406) 957-1576.

Someone interacted with a suspicious email or link?

Phenicie Business Management offers a free initial incident triage to help determine the next action.

TrustCan is a free tool from Phenicie Business Management, a Montana-based IT and cybersecurity provider.

Call (406) 957-1576