Free Tool · Email Security

Is This Email Genuine?

Paste the hidden delivery record from a suspicious email and get a plain-English answer in seconds — whether the sender really is who they claim to be, and what to do next.

Every email carries a technical record of how it actually reached you. It is the closest thing email has to a paper trail, and it is difficult to fake convincingly. This checker reads that record the way a security analyst would, then tells you what it found in ordinary language rather than jargon.

It is free, there is nothing to sign up for, and it works on any email from any provider.

The checker is just below

At a glance

Private — nothing you paste leaves your computer
Instant — a full answer in seconds, at no cost
Checks sender authentication and the full delivery chain
Written for business owners, not IT departments

Check your domain now

Type your domain and this checker reads what you have published to the internet, then tells you in plain English whether a stranger could send email in your name — and what is missing if they could.

What happens to what you type. Your domain name is looked up in the public DNS, the same directory every mail server uses. Nothing else leaves your browser, nothing is stored, and there is no sign-up. A domain name is public information — it is on your website and in every email you send.

Just the domain — yourbusiness.co.uk. An email address or a full web address works too; we will take the domain out of it.

Try an example

Found something you did not expect?

Locking a domain down properly takes an hour or two and it is permanent. I do this for a living — tell me what the checker said and I will tell you what it would take.

Talk to James

What this can and cannot tell you. It reports what your domain has published to the world, which is exactly what a receiving mail server looks at when it decides whether to trust a message. It cannot see inside your mail system, cannot confirm your mail is being signed correctly in practice, and cannot prove a signature is missing — only that it could not find one at the usual names. Treat it as a strong indication, not an audit.

Who wrote this

James Batt

CISSP CEH Founder, Systems Secure

Twenty-five years as an IT architect in the oil and gas industry, designing multi-million pound systems for companies around the world, before going independent. These days the work is smaller and a good deal more useful: helping UK businesses get enterprise-grade security without an enterprise budget.

I built this checker because the answer is usually sitting right there in the email, and you shouldn’t need to know somebody like me to read it. Check it yourself, at any hour, without sending your message to anyone.

If you want me to look into it more deeply, pick up the phone — or get in touch whichever way suits you.

No obligation · No sales script · You keep the findings either way

Questions you're probably asking

Is it safe to paste my email headers here?

Yes. Nothing you paste leaves your computer. The checker is a small piece of code that runs inside your own web browser, on your own machine — there is no upload, no server receiving anything, and nothing stored or logged at our end. If you want to prove it to yourself, disconnect from the internet once the page has loaded and the checker will still work perfectly. Headers do contain your email address and details of the servers involved, which is precisely why we built it this way.

Can email headers be faked?

Parts of them, yes — and that is exactly what the checks are for. Anyone can type whatever they like in the From line. It is no more reliable than the return address written on the back of an envelope. What is far harder to fake is the record each mail server adds as the message passes through, and the pass-or-fail verdicts your own mail provider stamps on it the moment it arrives. Those get added after the sender has lost control of the message. A forger can write a convincing From line, but they cannot make somebody else's server vouch for them.

It says the email passed — does that mean it's safe?

No, and this is the most important thing on the page. A pass means the message genuinely came from the domain printed on it. It tells you nothing about who was sitting at the keyboard. If a supplier's or a colleague's real account has been broken into, every email the criminal sends from it will pass every check here — because it really is their account. That is how most invoice and payment fraud against small businesses actually works. Treat a pass as one piece of evidence, not as permission. Anything involving bank details, a payment or a password still gets confirmed by phone, on a number you already had.

What does it mean when the result says "not recorded"?

It means those checks were not in the text you pasted, almost always because only part of the record was copied. The verdicts are added by your own mail provider and sit near the top of the record, so if you started copying partway down, they are missing. Go back and copy the whole block, starting from the very first line. You will also see it on internal email that never left your own systems, which is normal and not a cause for concern.

Does this work with Gmail, Outlook, anything else?

Yes. The delivery record is part of how email itself works, so every provider produces one and the checker reads them all the same way. The only thing that differs is where you click to find it, and the panel further up this page covers Outlook, Gmail and Apple Mail. One thing matters more than which provider you use: check the original email, not a forwarded copy. Forwarding rewrites the record, so you would be checking your own message rather than theirs.

I think someone is targeting my business — what should I do now?

Stop and confirm before you do anything else. If the email asked you to pay something, change bank details or log in somewhere, do not do it — and do not use any phone number or link taken from the email itself. Ring the organisation on a number you already had. If someone has already clicked, entered a password or made a payment, change that password immediately from a different device and tell your bank straight away. Then send it to me and I will look at it myself, at no charge. A live attempt on a business is rarely aimed at one person, so the rest of your team need to know today.

Should I report the email to anyone?

Yes, and it takes seconds. Forward suspicious emails to [email protected], the National Cyber Security Centre's reporting service. Scam text messages go to 7726, free from any UK mobile. If money has already gone or an account has been broken into, report it to Action Fraud on 0300 123 2040 or at reportfraud.police.uk, which covers England, Wales and Northern Ireland — in Scotland, report to Police Scotland on 101. It is worth doing: reporting is how fake websites get taken down before they catch somebody else.

Image

Innovation

Fresh, creative solutions.

Excellence

Excellence

FOLLOW US

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]

How to check you’re dealing with us

Serving Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support

Copyright 2026. Systems Secure. All Rights Reserved.