Paste the raw headers of a message (Gmail: Show original; Outlook: View message source). The analyzer unfolds them, reads the Received chain from the first hop to your mailbox with per-hop delays and the public/private type of every IP, extracts SPF/DKIM/DMARC results from Authentication-Results, lists DKIM signing domains, and flags what usually matters in phishing and delivery cases: Reply-To or Return-Path pointing elsewhere, unaligned DKIM domains, failed authentication, missing hops, clock skew and long queues. Nothing is looked up online. Everything runs locally.