How to Trace an Email: Reading Email Headers and Spotting Spoofed Messages
Email headers record every server a message passed through and its SPF, DKIM and DMARC results. How to get the raw headers, read Received lines bottom-up, the signs of a spoofed message, and the limits of IP tracing.
Email headers record every server a message passed through and its SPF, DKIM and DMARC results. How to get the raw headers, read Received lines bottom-up, the signs of a spoofed message, and the limits of IP tracing.
The email export teams fear most looks like it comes from a long-standing customer but asks to change the bank account for payment. The reliable way to judge it is not the display name but the headers.
Getting the raw headers
- Gmail: open the message, ⋮ at the top right, Show original.
- Outlook on the web: … → View → View message details.
- Outlook desktop: File → Properties → Internet headers.
- Other business mailboxes usually offer "View source" or "Show original" in a More menu.
Start with the authentication results
The Authentication-Results line is the receiving server's own verdict:
Authentication-Results: mx.google.com;
dkim=pass [email protected] header.s=s1;
spf=pass [email protected];
dmarc=pass (p=REJECT) header.from=example.com- dmarc=pass: the visible From domain was verified, so the message almost certainly came from a system that domain authorises.
- dmarc=fail: be very careful, it is likely forged. It can also mean the sender's domain is misconfigured, so confirm anything about payments by phone or another channel.
- No DMARC result: the sender's domain has no DMARC record, so this check cannot tell you either way.
Read the Received lines bottom-up
Each mail server adds a Received line at the top. The bottom line is closest to the sender and the top line is your own mail server. Reading upwards gives the delivery path, and the time difference between adjacent lines is how long the message spent at that hop.
Signs of spoofing and phishing
- DMARC or SPF shows fail or softfail.
- Reply-To is on a different domain from From, so your reply goes to someone else.
- The sender uses a look-alike domain, such as a digit 1 instead of the letter l or an extra hyphen.
- Urgency, a new bank account, or a link asking you to sign in.
The limits of IP tracing
People often hope the headers reveal where the sender is. Mail sent from webmail such as Gmail or Outlook usually shows only the provider's own server IPs, not the sender's, and a visible IP may be a VPN or proxy anyway. IPs are better for checking whether mail came from the organisation's usual mail system than for locating a person.
Email Header Analyzer
Paste raw headers to see SPF, DKIM and DMARC results, the delivery path and phishing signs. Runs locally; nothing is uploaded.
DMARC & SPF Checker
Check whether your own domain can be forged and how to fix it.