SiteAlertAI SiteAlertAI
🛰 Web Scan 🔒 SSL/TLS 📬 MX Record ✉ Email Header 🎣 URL Check 🌍 IP Geo
🛰 Web Scan 🔒 SSL/TLS 📬 MX Record ✉ Email Header 🎣 URL Check 🌍 IP Geo
← All articles
Email Security 2026-02-06 · 6 min read

How Email Spoofing Works — and How to Read a Header

The visible "From" address in an email is just a label — anyone can write anything there. Email spoofing exploits this to impersonate brands and colleagues, the foundation of most phishing and business-email-compromise attacks.

What the headers reveal

Every message carries technical headers that record its real journey:

  • Received: lines trace the servers the message passed through, bottom to top.
  • Authentication-Results: shows whether SPF, DKIM and DMARC passed or failed.
  • Return-Path and Reply-To can differ from the visible sender — a red flag when they do.

Spotting a spoof

A legitimate message from a real domain should show SPF and DKIM pass aligned with the From domain, and DMARC pass. Failures, mismatched domains, or a chain of unfamiliar relays all suggest forgery. Paste a raw header into the email header analyser to see the routing and authentication results decoded.

Put this into practice
Run a free, private scan — no login, nothing stored.
🛡 Web Scan 🔒 SSL/TLS 📬 MX & Email 🎣 URL Check

Related articles

Email Security SPF Records Explained: Stop Others Spoofing Your Email SPF tells the world which servers may send mail for your domain. Here is how to write one that actually protects you. Email Security DMARC: The Policy That Ties SPF and DKIM Together DMARC tells receivers what to do with mail that fails authentication — and reports who is sending as you. Here is how to roll it out. Email Security DKIM: How a Cryptographic Signature Proves Your Email Is Real DKIM adds a tamper-proof signature to your mail. Here is what it is and how to set it up correctly.
SiteAlertAI · © 2026 All rights reserved · Built for security professionals and developers.
Blog Guides Privacy Terms About Contact Social

⚠ For authorised security testing only. Scanning domains you do not own may violate laws in your jurisdiction. SiteAlertAI accepts no liability for misuse. CVE data is indicative — verify with NVD.