HEADERPROOF
Got an email that claims to be from your bank, your boss, or a service you use, and something feels off? Paste its raw headers and HEADERPROOF shows where the message actually originated and whether it passed the three checks that prove a sender is real (SPF, DKIM, DMARC), then flags the classic impersonation tricks. The verdict is free; the full breakdown needs a Sovereign pass.
In most mail apps: open the message, choose Show original / View source / View headers, and copy everything. Only the headers are needed, and nothing you paste leaves your browser.
HEADERPROOF runs entirely in your browser and never uploads anything. It reads the authentication results your receiving mail server already recorded in the headers and checks for common spoofing tells. A "looks authentic" result means the message passed those checks, not that its contents are safe or true, and a missing result usually just means your provider did not record one. When in doubt, do not click links or reply; contact the sender through a channel you already trust.