Email Header Analyzer & Hop Timeline
Paste the message headers to build a delivery timeline. Reported authentication results are read from the text, not independently verified.
Runs locally in your browserPaste the message headers to build a delivery timeline. Reported authentication results are read from the text, not independently verified.
Runs locally in your browserEmail Header & Hop Analyzer belongs to the network tools on KivTools. The workbench above handles the whole job on one screen: text you paste or type, then a text result you can copy.
The conversion runs inside the page with browser JavaScript. Nothing you enter is uploaded, the tool keeps working offline, and it is safe for data you are not allowed to send to a third party.
Web infrastructure problems are usually visible only from the outside: what DNS answers, which headers a server returns, whether a redirect loops or a certificate covers the hostname. These tools inspect a live endpoint from the public internet and report what an ordinary client would see.
A single probe is a snapshot, not a guarantee. GeoDNS, CDNs and caches can answer differently from another network, so compare results from a second vantage point before changing production settings.
Browsers, desktop tools and command-line utilities should agree on the result; a mismatch usually means a different encoding, locale or version. Reproduce the finding with the platform’s own tools (dig, curl -I, openssl s_client) before you act on it; the numbers should agree.
Timeouts and blocked ports often come from firewalls or ISPs on the path, not from the target service itself, which is why an external check is a useful second opinion. Keep a copy of the input while you experiment, so a wrong setting never destroys the source.
Input: pasted raw email headers. Output: Received-hop timeline, delay calculations, authentication summary, and spoofing flags such as missing identifiers or Reply-To domain mismatches.
Troubleshooting email delivery delays; investigating spoofed or phishing emails; auditing authentication results before forensic analysis.
The pasted email headers are processed locally in browser JavaScript and are not uploaded to KivTools.
It cannot validate DNS records or confirm sending-server identity; accuracy depends on complete, unmodified pasted headers.
Yes. Every tool on KivTools is free, needs no account and has no usage quota. There is no paid tier hiding behind the workbench, and no email address is required to use the result.
Inside your browser. The page loads a script once and the conversion happens on your machine, which is also why the tool still works when the network drops.
Input: pasted raw email headers. Output: Received-hop timeline, delay calculations, authentication summary, and spoofing flags such as missing identifiers or Reply-To domain mismatches. Large inputs are usually handled without trouble, but extremely large ones are better processed in a local command-line tool.
Caches and CDNs lie happily: check the authoritative source and a second resolver. Compare a small known-good sample first when the output feeds an automated pipeline.
The output is yours: no watermark, no licence tag, no attribution requirement. Check the underlying format or library licence when the result ships in a product.
The page works in any modern mobile browser, and the layout collapses to a single column on small screens. Local tools keep working offline once the page has loaded.