Reading Email Headers Without Being a Techie
Email headers show where a message really came from and whether it passed security checks. How to open them in common email apps and the few lines worth reading.

Every email carries hidden technical information called headers: the route it took, the servers involved, and the results of security checks. You do not need to understand all of it. A few lines can confirm whether an email really came from who it claims.
How to open headers
- Gmail (web): open the email, click the three-dot menu, choose "Show original".
- Outlook (web and new Outlook): open the email, use the three-dot menu, then "View" and "View message details" or similar.
- Apple Mail: choose View, then Message, then All Headers or Raw Source.
- Phones: most mobile apps do not show headers; use the web version on a computer.
Menu names change between versions; search your provider's help for "view headers" if needed.
The lines that matter
| Line | What to check |
|---|---|
| From | The claimed sender address. |
| Reply-To | Does it differ from the sender? That can be suspicious. |
| Return-Path | Where bounces go; a very different domain can be a clue. |
| SPF / DKIM / DMARC results | "pass" is good; "fail" or "softfail" for a brand's domain is a strong warning. See email authentication explained. |
| Received lines | The servers the email passed through, read from bottom (first) to top (last). |
A "pass" does not mean safe. It means the email really came from that domain, which could be a lookalike domain or a compromised account. Always judge the request too.
When headers help
- An email looks exactly like your bank's, and you want certainty.
- Your IT team or a reporting service asks for them.
- You suspect someone is spoofing your own organization.
Want a quicker check? Paste the email into CyberWatch AI Scan for a free second opinion.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
Do I need to read headers for every suspicious email?
No. Most phishing can be spotted by the request and the links. Headers are useful when you want extra evidence or need to report an email.
What does 'SPF fail' mean?
The sending server was not authorised by the domain the email claims to come from, which is a strong warning sign.
Is it safe to view headers?
Yes. Viewing headers does not open links or attachments.
Sources
- Avoid and report phishing emails, Gmail Help
- Suspicious email actions, UK National Cyber Security Centre
- Report a scam email, UK National Cyber Security Centre


