Free tools by Venmail

Make sense of your email headers.

See the SPF, DKIM and DMARC results recorded in a received email, understand what they mean, and decide what to check next.

  • Free · no account
  • Headers stay in your browser
  • Works with any mail provider

1. Add your headers

Open a received email and find Show original, View source or Message details. Copy the header lines above the blank line where the message body begins.

No upload, no storage, no DNS requests. Avoid pasting the message body. Maximum input: 256 Ki characters.

Privacy and optional usage measurement

The analyzer runs in this tab. Your pasted text is never included in analytics or sent to Venmail. The site uses its normal page analytics. Optional tool events contain only the action name and whether you used the sample.

2. Understand the results

These are reported results, not independent checks. Headers can be forged. Trust only entries added by your receiving mail provider; ask that provider if you are unsure which entry is theirs.

Your results will appear here after analysis.

SPF

SPF checks whether the sending server is authorized for the envelope sender. Forwarding can affect this result.

DKIM

DKIM checks a domain signature on the message. A message may have several signatures with different results.

DMARC

DMARC checks alignment with the visible From domain using SPF or DKIM. An SPF pass alone does not establish DMARC alignment.

Turn a result into a fix

Start with the guide that matches your situation. If you need a workspace for business email, explore Venmail’s Free plan and check the current sending limits.

Email going to spam?

Use a repeatable audit to separate authentication, list quality and placement problems.

Changed email providers?

Check a fresh message after migration before removing old DNS records.

Working from a bounce?

Use the actual SMTP response to distinguish authentication failures from other rejections.

How this tool works

It reads Authentication-Results fields, unfolds wrapped lines, and keeps each receiver entry separate. It does not send test mail, look up DNS or validate signatures. Received fields are counted as routing context, not proof of delivery. The parser recognizes common SPF, DKIM and DMARC status words; unusual formats may need manual inspection.

Authentication-Results format and trust limitations (RFC 8601)Find full headers in Gmail