Email header analysis for Outlook — by Ironline Security
headAnalyzer reads a message's full internet headers and analyzes them for signs of
spoofing and phishing: SPF / DKIM / DMARC / ARC authentication results,
the Received routing chain with per-hop timing and TLS, sender-identity
mismatches (display-name impersonation, lookalike/punycode domains), and upstream spam
verdicts — rolled up into a single verdict with ranked findings.
🔒 All analysis runs locally in your browser or Outlook task pane. No message data is ever
sent to a server. The site only serves the add-in's static code.
Install in Outlook
In new Outlook for Windows or Outlook on the web,
open aka.ms/olksideload.
Go to My add-ins → Custom Addins → Add a custom add-in → Add from URL…
Enter https://headanalyzer.ironlinesec.com/manifest.xml and confirm.
Open any message and click Analyze Headers on the ribbon.
Org-wide rollout: an admin can deploy the same manifest to everyone via the Microsoft 365
admin center (Integrated apps).
What it checks
Authentication — SPF, DKIM, DMARC, Microsoft CompAuth, and the full ARC chain.