무료 이메일 헤더 분석기

2025년 12월 02일 • 보안

이메일 헤더 분석하여 피싱 식별

이메일 헤더는 모든 메시지의 진정한 출처를 드러냅니다. 아래에 이메일 헤더를 붙여넣어 SPF, DKIM, DMARC 인증을 확인하고, 메시지 경로를 추적하며, 피싱 또는 스푸핑 시도를 나타낼 수 있는 경고 신호를 식별하세요. 모든 분석은 브라우저에서 이루어집니다.

How to get the raw email headers

The tool needs the full raw headers, not the visible message. In Gmail, open the email, click the three-dot menu and choose “Show original”. In Outlook, open the message, go to File then Properties, and copy the “Internet headers” box. In Apple Mail, use View then Message then Raw Source. Paste the whole block above.

What the results tell you

Headers record the path a message actually took and the results of the checks that prove who sent it. Focus on three: SPF (was the sending server authorised for that domain), DKIM (was the message cryptographically signed and unaltered), and DMARC (did the visible “From” line align with those checks). A “fail” or “none” on these, especially when the email asks for money, credentials, or urgency, is a strong spoofing signal. Our guide to email header red flags walks through real examples.

Browse the rest of our free security tools for password and file-integrity checks.

자주 묻는 질문

What are SPF, DKIM and DMARC?

They are email authentication checks. SPF verifies the sending server is authorised for the domain, DKIM verifies the message was signed and not altered, and DMARC ties both to the visible “From” address. Failures on these are common signs of spoofing.

Can headers prove an email is a scam?

They are strong evidence, not absolute proof. Failed authentication plus a suspicious request is a clear red flag, but a message can pass these checks and still be malicious if the sender’s own account was compromised. Combine the headers with judgement about what the email is asking for.

보안, Security Briefing의 사이버보안 저자

보안

admin은 정부 기술의 선임 스태프 작가입니다. 이전에는 PYMNTS와 베이 스테이트 배너에 글을 썼으며 카네기 멜론에서 문예창작 학사 학위를 받았습니다. 현재 보스턴 외곽에 거주하고 있습니다.

ko_KRKorean