What headers tell you
Every email carries a stack of headers. The Received headers, added by each mail server, form a routing chain — read them top to bottom for the full path (the last one is the original sender's server). Authentication-Results headers carry the receiving server's SPF/DKIM/DMARC verdicts, which is where phishing triage usually starts.
Reading the verdicts
- SPF checks the envelope sender:
pass/fail/softfail/neutral/none. Fail means the sending IP isn't authorized for that domain. - DKIM verifies the signature:
passmeans the domain ind=signed the message and it wasn't altered in transit. - DMARC ties them together with a policy (
p=):none(monitor),quarantineorreject.dmarc=passrequires SPF or DKIM alignment — the domain in the From header must match. - The From vs Reply-To check: legit mail rarely sets a Reply-To on a different domain than From; mismatch is a classic phishing tell.
How to get raw headers
Gmail: open the message → ⋮ → Show original. Outlook: ⋮ → View → View message source. Apple Mail: View → Message → Raw Source. Paste everything from Delivered-To or Return-Path onward.
This parser is heuristic — for forensic certainty, correlate with DNS records yourself. It never uploads your headers; everything is parsed locally.