Skip to content

Email Headers

The header fields that matter when tracing a message and checking whether it is what it claims to be.

Why It Matters

The parts of an email a user sees (display name, From address, subject) are easy to fake. The headers record which servers actually handled the message and whether it passed authentication, which is where spoofing and lookalike domains get caught.

Reference

Core Headers

Header Contents Notes
From The author's address, as shown to the recipient Required (RFC 5322); easy to spoof
Date When the message was written or sent Required (RFC 5322)
To, Cc Recipients
Subject Message subject
Message-ID Unique ID from the sending system Use it to search mail logs and message traces
Reply-To Where replies go Differs from From in many phishing emails
Return-Path Bounce address (envelope sender) The domain SPF is checked against
Received Added by each server that handled the message Read from the bottom up; the lowest is closest to the sender
Delivered-To The mailbox the message was delivered to
Content-Type Message format multipart/mixed usually means attachments

Authentication Headers

Header Contents
Received-SPF SPF result for the sending IP
DKIM-Signature The signature, signing domain (d=), and selector (s=) used to look up the public key in DNS
Authentication-Results SPF, DKIM, and DMARC results recorded by the receiving server

Custom X-Headers

Non-standard headers added by mail providers and security tools, such as X-Originating-IP, X-Mailer, and spam filter verdicts like X-MS-Exchange-Organization-SCL.

How I Use It

I always work from the original message, saved as an .eml or .msg file or pulled from the mail security portal, because forwarding a message replaces its headers. Then I paste the headers into an analyzer to get a readable hop-by-hop view, and check three things: the authentication results, whether From, Reply-To, and Return-Path agree, and where the bottom-most Received header says the message really came from.

Header Analyzers

Resources