Skip to content
Skip to main content
Email Evidence Technical Explainer

What is an email header?

An email header is the structured set of labelled fields that accompanies a message. Its fields describe presentation, addressing, identifiers and parts of the route through mail systems, but they do not all come from the same source or carry equal evidential weight.

A header contains several kinds of record

Familiar fields help a mail application display the message:

From: Alex Example <alex@example.org>
To: Sam Example <sam@example.net>
Subject: Meeting notes
Date: Fri, 7 Aug 2026 09:15:00 +0100
Message-ID: <example-value@example.org>

The visible From field is an identity presented by message-creation software, not proof that a person or account sent the email. Reply-To and Return-Path perform different roles and may legitimately contain different addresses.

Mail servers add Received fields as the message moves between systems. Because a receiving server normally places its new entry above earlier ones, the newest recorded hop appears at the top. Lower entries may come from infrastructure outside the recipient's trust boundary or may have been inserted before the message reached a reliable system. Interpret each Received line through the system that added it.

Authentication-Results fields can record SPF, DKIM and DMARC checks. They describe domains, routes and message integrity within each mechanism's scope; they do not prove who wrote the message. Results added by the recipient's provider carry a different status from text copied into an untrusted header.

Read fields according to their source and purpose

Message-ID values and Date fields are created by software and should not be treated as infallible. Several timestamps may describe composition, submission, filtering, receipt or delivery in different timezones.

MIME extends the message with body parts, alternative plain-text and HTML versions, and attachments. Individual parts have their own content type, filename and encoding fields. These sit within the MIME body structure rather than the main message header.

A complete header can contain repeated fields, folded lines, encoded text and provider-specific additions. An application's tidy details panel may omit, rearrange or decode them. Preserve the native message and full source before relying on a summary.

The header can support a limited account of how systems represented and handled the message. It does not alone establish authorship, account control, reading by the recipient or that a listed IP address belongs to the sender's device. Provider, account, device and contextual records may be needed to bridge those gaps.

Key takeaway

An email header is a layered technical record, not a certificate of origin. Interpret each field by who created it, what event it records and how independent evidence supports it.

Sources

Reference: EML-048Email Evidence