Every email you receive contains hidden diagnostic metadata known as the Email Header. While cybercriminals can easily spoof the "From:" display name (e.g. pretending to be your bank or PayPal), they cannot alter the cryptographic routing breadcrumbs stamped by Mail Transfer Agents (MTAs).
What Are "Received:" Headers?
When an email travels across the internet, every mail server that handles the message stamps a mandatory Received: from ... by ... with ... header at the very top of the message. By reading these stamps from bottom to top, you can trace the exact hop-by-hop journey back to the original sender's public IP address.
How to Extract Raw Email Headers:
- Gmail (Web): Open the email → Click the three vertical dots (More) next to the reply button → Select "Show original" → Click "Copy to clipboard".
- Microsoft Outlook (Office 365 / Desktop): Open message → File → Properties → Look inside the "Internet headers" box.
- Apple Mail (macOS): Open message → View → Message → Raw Source (or press
Cmd + Option + U).
Instant 1-Click Forensic Analysis:
Paste any raw email header into our automated parser to instantly extract the originating sender IP, geographical map, and SPF/DKIM validation status.
Open Email Header Forensics →Understanding Authentication Results: SPF, DKIM, and DMARC
Modern anti-spoofing protocols ensure message legitimacy:
- SPF (Sender Policy Framework): Verifies whether the sending server's IP is authorized in the domain's public DNS TXT records.
- DKIM (DomainKeys Identified Mail): Uses asymmetric cryptography to verify that the message content was not tampered with in transit.
- DMARC (Domain-based Message Authentication): Dictates what recipient servers should do (reject, quarantine, or deliver) if SPF or DKIM fail.