How Email Works

How to Read Email Headers and Spot a Fake Email

Diagram illustrating an email header showing network hops, IP address, and authentication status
On this page
  1. Where to Find Headers in Common Email Clients
  2. Key Fields in an Email Header Explained
  3. How to Read Authentication-Results: SPF, DKIM, and DMARC
  4. Header Fields Comparison Summary
  5. Step-by-Step Email Header Analysis to Spot Sender Spoofing
  6. Protect Your Inbox from Spoofing and Spam

To check where an email really came from, you need to view its raw internet message headers and trace the network hops recorded along the way. While the display name and "From" address in your email client can be easily forged, the underlying header records the originating IP address and cryptographic authentication checks. By inspecting lines like Received and Authentication-Results, you can perform an accurate email header analysis and determine whether a message is authentic or a fraudulent fake email designed to mislead you.

Every email you receive is accompanied by metadata that your mail client hides by default. This metadata works like postal stamps and dispatch logs stamped onto a physical envelope at each distribution center. Learning how to read email headers gives you the tools to verify legitimate business messages, debug delivery problems, and protect yourself from malicious spoofing attempts.

Where to Find Headers in Common Email Clients

Before you can analyze an email, you must view the raw, unformatted message data. Major email providers place this feature in slightly different menus, but all standard clients allow you to access the raw text.

Gmail (Web)

  1. Open the email you wish to inspect.
  2. Click the three vertical dots (More options) next to the reply arrow in the top-right corner of the message pane.
  3. Select Show original from the dropdown menu.
  4. A new tab will open displaying summary authentication results along with the full raw header text below. You can use the "Copy to clipboard" button to analyze it in a text editor.

For additional details on how Google processes these lines, refer to the official Gmail message header guide.

Microsoft Outlook (Web and Desktop)

  • Outlook on the Web: Open the message, click the three horizontal dots at the top right of the message window, choose View, and then select View message details.
  • Outlook Desktop (Windows): Double-click the email to open it in its own window. Click File > Properties. The header text appears in the box labeled Internet headers at the bottom of the dialogue window.

Microsoft outlines specific navigation steps for different versions in their Outlook Internet headers documentation.

Apple Mail (macOS)

  1. Select or open the email message.
  2. In the top menu bar, click View.
  3. Hover over Message and select All Headers (or press Shift + Command + H).
  4. The extended headers will expand directly above the body of the email.

Yahoo Mail

  1. Open the message.
  2. Click the More menu (represented by three horizontal dots) located above or beside the email content.
  3. Click View raw message to see the complete headers and MIME boundaries in a plain-text window.

Key Fields in an Email Header Explained

When you first view raw message data, you will encounter dozens of lines of technical jargon. You do not need to understand every parameter to check email sender authenticity. Focus your attention on these primary fields:

1. From vs. Return-Path

The From: line is what you see in your everyday inbox interface. Crucially, this is an arbitrary header field defined by the sending mail client. Just like writing any return address on the outside of an envelope, a sender can type whatever address they want into the From: field unless the receiving server strictly enforces authentication rules.

The Return-Path: (also known as the envelope sender or MAIL FROM address during delivery) indicates where automated bounce notifications and delivery error reports should be sent. If an email claims to be from support@bank.example.com in the From field, but the Return-Path points to an unrelated domain like bounce-handler@unknownserver.net, you should treat the message with extreme suspicion.

2. Received (The Server Hop Trail)

The Received: lines represent the most reliable evidence in an email header because they are added sequentially by each mail transfer agent (MTA) handling the message. Understanding the direction of these lines is critical:

Rule of thumb: Always read Received: headers from the bottom to the top. The line at the very bottom represents the first server that handled the message from the sender. The line at the very top was stamped by your own email provider when the message arrived at your inbox.

A typical Received entry looks like this:

Received: from mail.senderdomain.com (mail.senderdomain.com [198.51.100.24])
by mx.google.com with ESMTPS id abc123xyz...
for <recipient@example.com>;
Wed, 18 Oct 2023 10:14:02 -0700 (PDT)

This snippet tells you that Google's mail server received the message directly from the server at IP address 198.51.100.24. While an attacker can forge fake Received lines at the bottom of a message before sending it, they cannot falsify the header added by the receiving server that accepted the connection.

3. Message-ID

The Message-ID: is a unique string assigned by the mail system that generated the message. It usually ends with the domain name of the sending service (for example, <20231018171402.12345@mail.senderdomain.com>). If the domain in the Message-ID does not correspond to the purported sender, it warrants further investigation.

How to Read Authentication-Results: SPF, DKIM, and DMARC

Modern email security relies on cryptographic authentication to prevent domain impersonation. Your receiving mail server automatically evaluates these standards and appends an Authentication-Results: header summarizing its findings. Understanding how these protocols work is vital for verifying senders; you can read our deep dive on SPF, DKIM, and DMARC explained simply to understand the underlying mechanics.

Here is what the authentication fields tell you:

  • SPF (Sender Policy Framework): Verifies whether the sending server's IP address is authorized by the domain owner to transmit emails on their behalf. Results include:
    • pass: The sending IP is explicitly listed in the sender's domain DNS records.
    • fail: The sending IP is not authorized to send email for that domain.
    • softfail: The sending IP is probably not authorized, but the domain owner has configured a lenient policy.
    • neutral or none: The domain has not published definitive records.
  • DKIM (DomainKeys Identified Mail): Verifies that the message content was cryptographically signed by the sending domain and has not been altered in transit. Results include:
    • pass: The cryptographic signature matches the public key published in the domain's DNS.
    • fail: The signature is invalid or the message body was modified after signing.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance): Ties SPF and DKIM together by checking for "alignment"—confirming that the domain in the visible From: address matches the domains verified by SPF and DKIM. Results include:
    • pass: Both SPF/DKIM and domain alignment succeeded.
    • fail: The email failed alignment or underlying checks, and the domain owner's policy (none, quarantine, or reject) dictates how your server should handle it.

Header Fields Comparison Summary

The following table summarizes the key header fields you should inspect during an email header analysis:

Header FieldControlled ByReliabilityWhat to Check
FromSender clientLow (easily forged)Does the visible address match the expected organization?
Return-PathSending/Receiving MTAMediumDoes the bounce domain match the sending entity?
Received (Top)Your mail providerHigh (tamper-proof)Identifies the exact IP address delivering the mail into your inbox.
Received (Bottom)Originating MTAModerate to HighShows the first server hop, though forged bottom lines can exist.
Authentication-ResultsYour mail providerHigh (tamper-proof)Look for spf=pass, dkim=pass, and dmarc=pass.
Message-IDOriginating serverMediumCheck if the host suffix aligns with the sender's real infrastructure.

Step-by-Step Email Header Analysis to Spot Sender Spoofing

When an unexpected email lands in your inbox requesting action, password resets, or wire transfers, walk through these three practical steps to check the email sender:

Step 1: Check the Authentication Verdict

Search the raw header for the line starting with Authentication-Results:. Look for the DMARC and SPF status. If the email claims to come from an established company like PayPal or Google, but the header displays spf=fail, dkim=fail, or points to an unrelated domain like dmarc=fail (p=none) action=none header.from=suspiciousdomain.com, the email is an impersonation attempt.

Step 2: Trace the Bottom Received Hop

Scroll down to the earliest Received: header. Note the IP address enclosed in square brackets (e.g., [203.0.113.50]). You can copy this IP address into a public WHOIS lookup or IP reputation tool to see who owns the network block. If a message claiming to be from a UK utility provider originates from a residential IP block in an unrelated country, it did not originate from the company's official mail servers.

Step 3: Look for Domain Mismatches and Typosquatting

Attackers often register domains that look nearly identical to legitimate ones, substituting characters (e.g., an uppercase "I" for a lowercase "l", or adding a hyphen). Inspect the domain names in the Received: from and Return-Path: fields carefully. To understand the deeper architectural journey that messages follow between these servers, explore our overview of how email works with SMTP and MX records.

Warning: Never click links or download attachments found in an email while you are analyzing its headers. Even if a header looks convincing, sophisticated attackers may compromise legitimate accounts. If in doubt, reach out to the sender via a known, verified channel outside of email.

Protect Your Inbox from Spoofing and Spam

Inspecting raw headers is an invaluable skill for diagnosing questionable correspondence. However, manually auditing headers is time-consuming and unnecessary for routine web registrations, download gates, or exploratory account creations.

When signing up for one-off platforms, newsletters, or forums where you do not need permanent correspondence, using a temporary email address from FakeEmail.net helps keep unwanted mail from those signups out of your real inbox. A disposable email creates a clean buffer: incoming verification codes and confirmation links appear instantly in a temporary browser session, while your personal address remains completely hidden from marketing lists and data breaches.

By combining proactive inbox hygiene with the ability to read technical email headers, you can significantly improve your email security and better manage your digital footprint.

Frequently asked questions

Can email headers be completely faked?

Only partially. An attacker can write fake From, Return-Path, and even inject bogus Received lines at the very bottom of the raw email. However, they cannot fake the Received lines stamped by your own email provider or the Authentication-Results generated by your receiving server.

Why does an email pass SPF but still look like phishing?

An attacker can register their own malicious domain (e.g., evil-bank.com) and configure valid SPF and DKIM records for it. The message will pass technical authentication for that specific domain, but the content may still attempt to trick you into believing it is a different company.

What does 'Received: from localhost' mean in a header?

It indicates that the message originated from a local script, web application, or automated software running directly on that server before being handed off to the outgoing mail agent for internet delivery.

Can I trace a sender's physical home location from an email header?

Rarely. Most modern webmail providers (like Gmail, Outlook, and Yahoo) strip the sender's personal residential IP address from outgoing headers to protect privacy, replacing it with the IP address of their own webmail servers.

Need a disposable address right now? Get one free in a single click — no sign-up.

Get a temp email

A tech enthusiast and content strategist tracking the pulse of digital transformation, AI, and emerging tools. He specializes in breaking down complex innovations into actionable, reader-friendly insights. When he is not writing, you will likely find him testing new productivity apps over a fresh cup of coffee.

Written with AI assistance and checked against our editorial standards. Editorial Policy

Keep reading