The UK Small Business
Email Deliverability Experts

How to Read Email Headers (and What They Tell You)

Document and magnifying glass icon: email headers
This guide explains how to find the hidden 'headers' on any email and read the few lines that matter.

Every email carries a hidden log of where it came from, which servers handled it and whether it passed its security checks. When an email lands in spam, arrives late or looks fake, the headers usually say why. You only need to read five or six lines.

What email headers are

The part of an email you normally see (From, To, Subject, Date) is only a summary. Behind it sits the full header: anything from 30 to 100 lines of technical text.

Each server that handles the email adds its own lines to the top as the message travels. That makes headers the nearest thing email has to a tracking history.

 

How to see the full headers

Open the email first, then:

  • Gmail: click the three dots next to Reply, then ‘Show original’. Gmail shows a summary of the SPF, DKIM and DMARC results above the full text.
  • Outlook on the web, Outlook.com and new Outlook: click the three dots at the top of the message, then View, then ‘View message details’.
  • Classic Outlook for Windows: double-click the email to open it in its own window, then choose File, then Properties. The headers are in the ‘Internet headers’ box.
  • Outlook for Mac: right-click the message in the list and choose ‘View Source’.
  • Apple Mail on a Mac: choose View, then Message, then ‘All Headers’.
  • Thunderbird: choose View, then ‘Message Source’ (Ctrl+U).
  • Yahoo Mail: click the three dots, then ‘View raw message’.

Most phone apps don’t show full headers. Open the same mailbox on a computer or in webmail instead.

You need the headers from the copy that was received. The copy in your Sent folder doesn’t show what happened after it left you. If your emails are going to a customer’s spam folder, ask them to forward the email to you as an attachment, which keeps the headers. A normal forward strips them out.

 

The lines worth reading

Header What it tells you
From The address the reader sees. On its own it is easy to fake.
Return-Path Where bounce messages go. This is the address SPF checks.
Reply-To Where replies go, if that is different from the From address.
Received One line for each server that handled the email, with a time stamp.
Authentication-Results The receiving server’s verdict on SPF, DKIM and DMARC.
DKIM-Signature The digital signature. The d= part shows which domain signed the email.
Message-ID A unique reference, useful when you ask a provider to trace an email.

 

Read the 'Received' lines from the bottom up

The oldest ‘Received’ line is at the bottom. Each server adds its line above the last, so read upwards to follow the email from sender to inbox.

Every line ends with a time stamp. A gap of minutes or hours between two lines shows which server held the message up. Check the time zone at the end of each stamp (+0000, +0100, -0700) before you compare them.

Only the top few lines, added by your own email provider, can be fully trusted. Lines further down were written by servers the sender controls, and scammers sometimes invent them.

 

Authentication-Results: the most useful line

This is where the receiving server records whether the email passed its checks. A healthy one looks like this:

Authentication-Results: mx.google.com;
   dkim=pass header.i=@yourcompany.co.uk header.s=google;
   spf=pass smtp.mailfrom=jane@yourcompany.co.uk;
   dmarc=pass (p=NONE) header.from=yourcompany.co.uk
  • spf=pass means the sending server is on the domain’s approved list.
  • dkim=pass means the signature is intact. The domain after header.i= or header.d= is the one that signed.
  • dmarc=pass means at least one of those passed and matches the domain in the From address.

Other results you may see are fail, softfail, neutral, none (no record exists) and permerror (the record is broken, for example two SPF records on one domain).

The common trap is spf=pass and dkim=pass next to dmarc=fail. That means the checks passed for a different domain from the one in your From address. It usually happens when a website, newsletter tool or booking system sends as you but signs with its own domain. Our guide to SPF, DKIM and DMARC explains how the three fit together.

 

Why did it go to spam? The spam-filter lines

Some providers record their spam decision in the headers.

  • Microsoft 365 and Outlook.com: look for SCL: inside the X-Forefront-Antispam-Report line. SCL is the spam confidence level: -1 means filtering was skipped, 0 or 1 means not spam, 5 or 6 means spam, and 8 or 9 means high-confidence spam.
  • Web hosts and smaller providers: look for X-Spam-Status or X-Spam-Score. These often list the exact rules the email broke.
  • Gmail: it doesn’t publish a score. Open the email in the Spam folder and read the banner at the top, which gives a short reason.

If the checks all pass and the email still went to spam, the cause is usually reputation or content. See Why are my emails going to spam?.

 

Using headers to spot a fake email

Check these four things on any email you don’t trust:

  1. Does the domain in From match the domains in Return-Path and the DKIM d= value?
  2. Does Reply-To point somewhere else, such as a free Gmail address?
  3. Does the Authentication-Results line say dmarc=fail?
  4. Does the earliest trustworthy ‘Received’ line name a server that has nothing to do with the supposed sender?

One mismatch is not proof. Genuine newsletters often use a different Return-Path, because a mailing service sends them. Several mismatches together, plus a request for money or a password, is a strong sign of a fake.

 

Free tools that read headers for you

You can paste headers into a free analyser, which lays out each hop and delay as a table:

Headers include email addresses and server names, so only paste them into tools you trust. Copy the headers only, not the message underneath.

 

Need help fixing this?

We provide:
  • Free initial assessment
  • Clear explanation of the issue
  • Fixed-price solutions
  • UK-based support

Send us the headers from the email that went wrong and we’ll tell you what they show.

Get in touch
Online now: Amanda, our supportive AI Agent, 24/7
Pop in your details below and we'll bring you straight into the conversation.
We never phone. We'll only text you the link to your private ticket chat, so you can still reach us if your email stops working.
Please fill in the required fields.
Emails going to spam
Website not sending emails
Not sure what's wrong
Set up business email