{"id":89,"date":"2026-08-28T14:00:00","date_gmt":"2026-08-28T13:22:50","guid":{"rendered":"https:\/\/easyextract.online\/blog\/how-to-read-email-headers\/"},"modified":"2026-09-26T13:31:51","modified_gmt":"2026-09-26T13:31:51","slug":"how-to-read-email-headers","status":"publish","type":"post","link":"https:\/\/easyextract.online\/blog\/how-to-read-email-headers\/","title":{"rendered":"How to Read Email Headers (And What They Tell You)"},"content":{"rendered":"<p><!-- ============================ BODY ============================ --><\/p>\n<p><strong>Email headers are the routing log attached to every message \u2014 they record every server the email passed through, the real sender address, authentication results (SPF, DKIM, DMARC), and timestamps.<\/strong> Your inbox only shows you the friendly display name; the header shows you everything the servers saw. Whether you received a suspicious email and want to trace it, or you&#8217;re a developer debugging delivery failures, the header has the answer.<\/p>\n<h2>Where to find email headers<\/h2>\n<p>Every major client exposes the full header, but the menu path differs:<\/p>\n<ul>\n<li><strong>Gmail<\/strong> \u2014 Open the email \u2192 three-dot menu (top-right) \u2192 <em>Show original<\/em>. The raw source opens in a new tab.<\/li>\n<li><strong>Outlook (web)<\/strong> \u2014 Three-dot menu \u2192 <em>View<\/em> \u2192 <em>View message source<\/em>.<\/li>\n<li><strong>Outlook (desktop)<\/strong> \u2014 File \u2192 Properties \u2192 scroll to the <em>Internet headers<\/em> box.<\/li>\n<li><strong>Apple Mail<\/strong> \u2014 View \u2192 Message \u2192 <em>All Headers<\/em>.<\/li>\n<li><strong>Thunderbird<\/strong> \u2014 View \u2192 Headers \u2192 <em>All<\/em>.<\/li>\n<\/ul>\n<p>If you have a <code>.eml<\/code> file, open it directly in the <a href=\"https:\/\/easyextract.online\/eml-viewer\/\">EML viewer<\/a> to see the headers alongside the message body without needing a mail client. For <code>.msg<\/code> files (Outlook format), the <a href=\"https:\/\/easyextract.online\/msg-viewer\/\">MSG viewer<\/a> shows headers too.<\/p>\n<h2>The key headers explained<\/h2>\n<h3><code>From:<\/code><\/h3>\n<p>The display name and address the sender chose. <strong>This field can be freely forged<\/strong> \u2014 it is what appears in your inbox, but it carries no authentication on its own.<\/p>\n<pre><code>From: \"PayPal Support\" &lt;support@paypal.com&gt;<\/code><\/pre>\n<h3><code>Return-Path:<\/code><\/h3>\n<p>Where bounce messages (delivery failures) are sent. Because bounce handling is automated, this address is harder to fake convincingly. When <code>From:<\/code> is spoofed, <code>Return-Path:<\/code> often reveals the actual sending domain.<\/p>\n<pre><code>Return-Path: &lt;bounce@mail.actualsender.com&gt;<\/code><\/pre>\n<h3><code>Reply-To:<\/code><\/h3>\n<p>Where your reply goes if it differs from <code>From:<\/code>. Phishing emails frequently set this to an address the attacker controls so that victim replies land in their inbox, not the impersonated brand&#8217;s.<\/p>\n<h3><code>Received:<\/code><\/h3>\n<p>One line per server hop, stacked newest-first. Each line records the receiving server, the server it accepted the message from, and a timestamp. Reading from the bottom up traces the message&#8217;s full route from origin to your inbox. This is the most important header for tracing delivery.<\/p>\n<h3><code>Message-ID:<\/code><\/h3>\n<p>A unique identifier assigned by the originating mail server. The domain after the <code>@<\/code> usually reveals the true sending server \u2014 even when <code>From:<\/code> names a different domain.<\/p>\n<pre><code>Message-ID: &lt;abc123@mail.actualsender.com&gt;<\/code><\/pre>\n<h3><code>X-Originating-IP:<\/code> \/ <code>X-Forwarded-For:<\/code><\/h3>\n<p>The original client IP address, written by some servers (Google Workspace, Yahoo Mail, and others include it). Not universally present and can be forged by a rogue server, but useful when it appears.<\/p>\n<h3><code>Authentication-Results:<\/code><\/h3>\n<p>The receiving server&#8217;s verdict on three authentication checks:<\/p>\n<table>\n<thead>\n<tr>\n<th>Check<\/th>\n<th>What it verifies<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>SPF<\/strong><\/td>\n<td>Did this email arrive from a server the domain&#8217;s DNS has authorised to send mail?<\/td>\n<\/tr>\n<tr>\n<td><strong>DKIM<\/strong><\/td>\n<td>Was the message cryptographically signed by the sending domain, and is that signature intact?<\/td>\n<\/tr>\n<tr>\n<td><strong>DMARC<\/strong><\/td>\n<td>Does the domain publish a policy for what to do when SPF or DKIM fails (quarantine, reject, or nothing)?<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<pre><code>Authentication-Results: mx.google.com;\n  spf=pass smtp.mailfrom=actualsender.com;\n  dkim=pass header.d=actualsender.com;\n  dmarc=pass<\/code><\/pre>\n<h3><code>Date:<\/code><\/h3>\n<p>When the sender&#8217;s client submitted the message. Compare this with the timestamps on <code>Received:<\/code> lines to spot unusual delays \u2014 a gap of hours between hops may indicate queuing problems or a grey-listed server.<\/p>\n<h3><code>X-Spam-Score:<\/code> \/ <code>X-Spam-Status:<\/code><\/h3>\n<p>Set by the receiving server&#8217;s spam filter. Format and thresholds vary by provider (SpamAssassin, Postfix, etc.), but a high score or <code>Yes<\/code> status means the filter flagged the message before it reached your inbox.<\/p>\n<h2>How to spot a spoofed or phishing email<\/h2>\n<p>Three header checks catch the majority of spoofed messages:<\/p>\n<ol>\n<li><strong><code>From:<\/code> domain \u2260 <code>Return-Path:<\/code> domain.<\/strong> A legitimate transactional email from paypal.com will have a <code>Return-Path:<\/code> that also resolves to paypal.com or a known PayPal delivery partner. A mismatch is a strong red flag.<\/li>\n<li><strong><code>Authentication-Results:<\/code> shows <code>spf=fail<\/code> or <code>dkim=fail<\/code>.<\/strong> The message claims to be from a domain it has no authority to send from, or the message was modified after signing.<\/li>\n<li><strong><code>Reply-To:<\/code> points to a different domain than <code>From:<\/code>.<\/strong> Your reply goes somewhere unexpected \u2014 usually the attacker&#8217;s inbox.<\/li>\n<\/ol>\n<p>A real spoofed-header example:<\/p>\n<pre><code>From: \"PayPal\" &lt;security@paypal.com&gt;\nReturn-Path: &lt;bounce@mail347.phishingdomain.ru&gt;\nReply-To: &lt;collect@freemail.example&gt;\nAuthentication-Results: spf=fail; dkim=none<\/code><\/pre>\n<p>This message claims to be from PayPal. The <code>Return-Path:<\/code> is a Russian domain with no connection to PayPal. SPF failed \u2014 meaning PayPal&#8217;s DNS records do not list that server as authorised. DKIM is absent entirely. All three checks fail. Treat any email with this pattern as a phishing attempt.<\/p>\n<h2>Reading <code>Received:<\/code> headers in order<\/h2>\n<p><code>Received:<\/code> lines stack newest-first. To trace the message&#8217;s route, read from the <strong>bottom up<\/strong>. The bottom line is the first hop \u2014 the originating server. Here is a three-hop example:<\/p>\n<pre><code>Received: from mail.yourprovider.com (mail.yourprovider.com [203.0.113.10])\n        by mx.recipient.com with ESMTP; Fri, 28 Aug 2026 09:05:12 +0000\n\nReceived: from relay.sendingdomain.com (relay.sendingdomain.com [198.51.100.44])\n        by mail.yourprovider.com with ESMTP; Fri, 28 Aug 2026 09:04:58 +0000\n\nReceived: from client.sendingdomain.com (unknown [192.0.2.7])\n        by relay.sendingdomain.com with ESMTP; Fri, 28 Aug 2026 09:04:41 +0000<\/code><\/pre>\n<p>Reading bottom to top:<\/p>\n<ol>\n<li><strong>Hop 1 (bottom):<\/strong> The sender&#8217;s client at <code>192.0.2.7<\/code> handed the message to <code>relay.sendingdomain.com<\/code> at 09:04:41.<\/li>\n<li><strong>Hop 2 (middle):<\/strong> The relay passed it to <code>mail.yourprovider.com<\/code> at 09:04:58 \u2014 a 17-second transit, normal.<\/li>\n<li><strong>Hop 3 (top):<\/strong> Your provider delivered it to the final mail server at 09:05:12 \u2014 14 seconds more. Total delivery: 31 seconds.<\/li>\n<\/ol>\n<p>Any hop showing a delay of many minutes is worth investigating \u2014 it often points to a greylist hold, a delivery retry, or a misconfigured relay.<\/p>\n<h2>Extract email addresses from headers or logs<\/h2>\n<p>If you are working with email data at scale \u2014 parsing header dumps, mail server logs, or exported <code>.eml<\/code> files \u2014 and need to pull every address out into a list, the <a href=\"https:\/\/easyextract.online\/email-extractor\/\">email address extractor<\/a> does that in seconds. Paste or drop in your text; it finds every valid address. Nothing is uploaded \u2014 the extraction runs in your browser.<\/p>\n<section class=\"faq-section\">\n<h2>Frequently asked questions<\/h2>\n<details>\n<summary>How do I view full email headers?<\/summary>\n<p>In Gmail, open the email, click the three-dot menu, and choose <em>Show original<\/em>. In Outlook on the web, use the three-dot menu \u2192 View \u2192 View message source. In Apple Mail, go to View \u2192 Message \u2192 All Headers. In Thunderbird, go to View \u2192 Headers \u2192 All.<\/p>\n<\/details>\n<details>\n<summary>What does the Received: header tell you?<\/summary>\n<p>Each <code>Received:<\/code> line records one server hop \u2014 the receiving server, the sending server, and the timestamp. They stack newest-first, so reading from the bottom traces the route from the originating server to your inbox.<\/p>\n<\/details>\n<details>\n<summary>How can I tell if an email is spoofed?<\/summary>\n<p>Check three things: whether the <code>From:<\/code> domain matches the <code>Return-Path:<\/code> domain; whether <code>Authentication-Results:<\/code> shows <code>spf=pass<\/code> and <code>dkim=pass<\/code>; and whether <code>Reply-To:<\/code> points to the same domain as <code>From:<\/code>. A mismatch on any of these is a red flag.<\/p>\n<\/details>\n<details>\n<summary>What is DKIM and why does it matter?<\/summary>\n<p>DKIM (DomainKeys Identified Mail) is a cryptographic signature added to the message by the sending server. A <code>dkim=pass<\/code> result means the message was not modified in transit and genuinely came from the signing domain. A <code>dkim=fail<\/code> means either the message was altered after signing, or the sender forged the <code>From:<\/code> address.<\/p>\n<\/details>\n<\/section>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How do I view full email headers?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"In Gmail, open the email, click the three-dot menu, and choose Show original. In Outlook on the web, use the three-dot menu \u2192 View \u2192 View message source. In Apple Mail, go to View \u2192 Message \u2192 All Headers.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What does the Received: header tell you?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Each Received: line records one server hop \u2014 the receiving server, the sending server, and the timestamp. They stack newest-first, so reading from the bottom traces the route from origin to inbox.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How can I tell if an email is spoofed?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Check three things: whether the From: domain matches the Return-Path: domain; whether Authentication-Results shows spf=pass and dkim=pass; and whether Reply-To: points to the same domain as From:. A mismatch on any of these is a red flag.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is DKIM and why does it matter?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DKIM (DomainKeys Identified Mail) is a cryptographic signature added to the message by the sending server. A dkim=pass result means the message was not modified in transit and genuinely came from the signing domain. A dkim=fail means either the message was altered or the sender forged the From: address.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n<p><em>Last updated: 2026-08-28.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Email headers are the routing log attached to every message \u2014 they record every server the email passed through, the real sender address, authentication results (SPF, DKIM, DMARC), and timestamps. Your inbox only shows\u2026<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"slim_seo":[],"footnotes":""},"categories":[3],"tags":[],"class_list":["post-89","post","type-post","status-publish","format-standard","hentry","category-guides"],"_links":{"self":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/89","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/comments?post=89"}],"version-history":[{"count":2,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/89\/revisions"}],"predecessor-version":[{"id":166,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/posts\/89\/revisions\/166"}],"wp:attachment":[{"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/media?parent=89"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/categories?post=89"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/easyextract.online\/blog\/wp-json\/wp\/v2\/tags?post=89"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}