✓ No signup required Header-focused analysis Plain-English results
Email Header Analyzer

Paste the raw email headers

Use the original header data from your mail client so ScamKit can inspect authentication results, relay path, and signs of sender spoofing.

SPF / DKIM / DMARC
Detailed review

Best for suspicious invoices, fake account alerts, and emails that look real but still feel off. Paste headers, not just the body text.

Quick Answer

How ScamKit helps you decide if an email is real

ScamKit reads the raw email headers and checks SPF, DKIM, and DMARC — the authentication records that show whether the mail really came from the domain it claims. A failing or misaligned result is the strongest technical sign of a spoofed sender.

Reviewed by · Last updated June 2026 · See the ScamKit methodology.

Email Safety FAQ
How can I tell if an email sender is spoofed?

Check the raw headers for SPF, DKIM, and DMARC results. If the visible From address claims a brand but those checks fail or point at an unrelated domain, the sender is likely spoofed.

What do SPF, DKIM, and DMARC actually verify?

SPF verifies the sending server is authorized, DKIM verifies the message was signed and unaltered, and DMARC verifies the From address aligns with both. Legitimate brand email normally passes all three.

Can an email pass SPF and DKIM and still be a scam?

Yes. Scammers can pass authentication with their own lookalike domains, so a pass only proves which domain sent it. Check the domain itself, and treat urgent payment or login requests with suspicion — the phishing patterns guide shows real examples.

Related Guides