Break down an email's raw headers to trace its path and check for spoofing.
SPF checks whether the sending server is authorised to send mail for that domain. DKIM verifies a cryptographic signature proving the message wasn't altered in transit. DMARC ties the two together and tells receiving servers what to do if they fail — together, they're the main defences against email spoofing.
Each Received header records one server the email passed through, added by that server — reading from bottom to top shows the actual path the email took from sender to your inbox, which is harder to fake than the visible From address.
No — everything is parsed and displayed entirely in your browser using plain JavaScript, and it's never uploaded.