====== Email Headers ====== An **Email Header** contains critical metadata that accompanies every email sent across the internet. While standard mail clients usually hide this information to show only the sender, recipient, subject, and date, the full header contains the complete trace of every server, IP address, and security check the email passed through from sender to recipient. Analyzing raw email headers is essential for investigating email delivery delays, spoofing attempts, spam classifications, and authentication failures. ---- ===== Anatomy of an Email Header ===== Email headers consist of standard key-value pairs formatted as ''Header-Name: Value''. They are appended sequentially as an email travels across the network, meaning **the newest routing information appears at the top**, while the original sending server details appear at the bottom. ==== Core Header Fields ==== ^ Header Tag ^ Description ^ Example ^ | **Received:** | Added by each mail transfer agent (MTA) that handles the message. Contains IP addresses, timestamps, and TLS details. | ''Received: from mail.example.com (mail.example.com [192.0.2.1]) ...'' | | **Authentication-Results:** | Summary of authentication checks performed by the receiving server ([[email:dns-configuration:spf|SPF]], [[email:dns-configuration:dkim|DKIM]], [[email:dns-configuration:dmarc|DMARC]]). | ''dkim=pass header.i=@example.com header.s=s1; dmarc=pass ...'' | | **DKIM-Signature:** | Cryptographic signature verifying message integrity and domain authenticity. | ''v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=s1; ...'' | | **From:** | The address displayed to the recipient (Header From). | ''John Doe '' | | **Return-Path:** | The actual envelope sender address used for delivery error notifications and bounces. | '''' | | **Message-ID:** | A unique string generated by the originating server to identify the message. | ''<20260803.123456@mail.example.com>'' | | **X-Forefront-Antispam-Report:** / **X-Spam-Status:** | Custom spam and threat filtering scores added by security gateways. | ''SCL:1; SRV:BULK; CAT:NONE'' | ---- ===== How to Trace Mail Delivery (Reading "Received:" Headers) ===== To trace the route an email took, read the ''Received:'' headers **from bottom to top**: [Hop 3 - Top / Newest] Received: from mx.google.com (mx.google.com. [172.217.215.27]) by inbound-smtp.gmail.com with SMTP id x123 for ; Mon, 03 Aug 2026 12:00:02 -0000 [Hop 2 - Middle] Received: from relay.telenegar.ir (relay.telenegar.ir [198.51.100.10]) by mx.google.com with ESMTP id y456 for ; Mon, 03 Aug 2026 12:00:01 -0000 [Hop 1 - Bottom / Origin] Received: from mail.example.com (mail.example.com [192.0.2.1]) by relay.telenegar.ir with ESMTP id z789 for ; Mon, 03 Aug 2026 11:59:58 -0000 ==== Key Diagnostic Insights ==== * **Network Delays:** Calculate the time difference between timestamps in consecutive hops to pinpoint where delays occurred. * **Original Sender IP:** The bottom-most ''Received:'' header shows the true originating IP address of the sender (`192.0.2.1` in the example above), regardless of what is written in the ''From:'' line. ---- ===== How to View Full Headers in Popular Email Clients ===== ^ Email Client ^ Instructions ^ | **Gmail** | Open email -> Click three dots (More) next to Reply -> Click **"Show original"**. | | **Microsoft Outlook (Desktop)** | Open email -> Go to **File** -> **Properties** -> Copy text from **Internet headers**. | | **Outlook Web (OWA)** | Open email -> Click three dots (...) menu -> **View** -> **View message details**. | | **Apple Mail** | Open email -> Go to **View** menu -> **Message** -> **Raw Source** (or `Cmd + Option + U`). | | **Thunderbird** | Open email -> Go to **View** -> **Message Source** (or `Ctrl + U`). | ---- ===== Common Troubleshooting Scenarios ===== ==== 1. Spoofing & Phishing Detection ==== If an email claims to be from `support@bank.com`, but the bottom ''Received:'' header shows an unrelated IP address or domain, the message is likely spoofed. Check the ''Authentication-Results'' line for `spf=fail` or `dmarc=fail`. ==== 2. Email Delivery Delays ==== If an email arrived 30 minutes late, inspect the timestamps across all ''Received:'' hops to identify which specific MTA delayed processing or greylisted the connection. ==== 3. Unnecessary Bounce Errors ==== If emails bounce with 5xx status codes, inspect the ''Return-Path'' and ''Received-SPF'' headers to ensure SPF alignment isn't broken during forwarding. ---- ===== Verification & Diagnostics with Telenegar ===== You can verify and test your email headers and infrastructure using **Telenegar Tools**: ==== Using Telenegar Tools ==== * **Email Authentication Audit:** Verify your domain's SPF, DKIM, and DMARC parameters before sending with the [[tools:mailcheck|Telenegar Mail Check Tool]]. * **DNS Verification:** Check the resolution of mail server hostnames found in headers using the [[tools:dnscheck|Telenegar DNS Check Tool]]. ---- ===== Related Documentation ===== * [[tools:mailcheck|Telenegar Mail Check Tool]] — Analyze email authentication mechanisms and mail server responses. * [[tools:dnscheck|Telenegar DNS Check Tool]] — Validate hostnames and reverse IP (PTR) lookups. * [[email:troubleshooting:bounces|SMTP Status Codes & Email Bounces]] — Understand non-delivery codes returned in bounce headers. * [[email:dns-configuration:spf|SPF]], [[email:dns-configuration:dkim|DKIM]] & [[email:dns-configuration:dmarc|DMARC]] — The core authentication protocols recorded in headers. * [[networking:dns:reverse-dns|Reverse DNS (PTR Records)]] — Verify matching PTR records for originating IPs found in headers.