COMPLIMENTARY TOOL  //  find out which gateway handled or blocked your message Apply

EMAIL HEADER ANALYZER

Find out what actually happened to your message

Paste the raw headers. Get the authentication verdict, DMARC alignment, every delivery hop with its delay, and the security gateway that handled it. Nothing is uploaded and nothing is stored.

Updated July 2026

The short answer:

Headers record the delivery in reverse order, newest hop first. Read three things: the Authentication-Results line for SPF, DKIM and DMARC, whether the From domain matches the Return-Path and DKIM signing domain, and which host names appear in the Received chain. Those host names tell you who filtered you.

In Gmail: open the message, three-dot menu, Show original. In Outlook: File, Properties, Internet headers.
Paste headers above to see the analysis.

Questions people actually ask

Why does the hop order look backwards?

Each server prepends its own Received line as the message passes through, so the newest hop sits at the top and the original sender is at the bottom. This tool renumbers them into real delivery order, oldest first, and shows the gap between each pair.

SPF passed but DMARC failed. How?

Alignment. DMARC does not just want SPF or DKIM to pass, it wants the passing domain to match the domain in the visible From header. A sequencer sending with its own Return-Path will pass SPF for that domain and still fail DMARC, because the From says something else. This tool compares all three domains for you.

What is a security gateway and why does it matter for cold email?

Products like Mimecast, Proofpoint, Barracuda and Cisco IronPort sit in front of a company's real mailboxes and filter on policy before the mail server ever sees the message. They reject unknown senders as a rule, not because your address list was wrong. In our own campaign data, recipients behind a gateway were 9.5% of the list but 38.2% of the bounces, with roughly a 13% bounce rate against about 2.2% for everyone else.

What is a normal delay between hops?

Under a second is typical inside one provider. A single hop of 30 seconds or more usually means greylisting or content scanning. Minutes at the receiving gateway is a deliberate tarpit applied to senders it does not trust yet, which is a reputation signal worth acting on.

Is anything I paste sent anywhere?

No. This page makes no network requests at all. The parsing happens entirely in your browser, which matters because headers contain recipient addresses, internal host names and internal IP ranges. Nothing reaches ReplyLead.

Headers clean and still not landing?

Authentication is necessary, not sufficient. Placement also turns on domain age, volume ramp, list quality and who is filtering on the receiving side.

Apply to work with us

All free tools  //  Deliverability checker  //  SPF and DMARC generator  //  Why verified lists bounce