Not sure if an email is really from your bank, or a scammer pretending? Paste its raw source
and this reads the hidden authentication and flags the classic phishing tells — a reply-to that
goes somewhere else, a sender that doesn’t add up.
🔒 Checked on your device — nothing is sent anywhere, works offline.
📋 How to get the raw source: in Gmail open the message → ⋮ menu → “Show original.”
In Outlook → “View source”/“View message source.” On Apple Mail → View → Message → Raw Source.
Copy it all and paste below.
What this tells you — and what it can’t
SPF / DKIM / DMARC are stamps your mail provider adds saying whether the email really came from the
domain it claims. This reads those, and checks the reply-to and return-path against the sender.
Authentication passing means the domain is genuine — not that the message is safe. A real
domain can be look-alike (paypa1.com) or compromised. Always read the actual domain carefully.
If there’s no authentication stamp, this can’t verify the email from the headers alone — treat it
with caution and lean on the reply-to / sender checks.
When in doubt, don’t click links or reply — reach the company through a number or site you already trust.
Everything here runs in your browser; nothing is sent.
Free to copy, run, and reuse (CC0). A small, honest tool. (“Email Check” is a working name.)