← reportedandignored.org

How to read email headers to find who really sent it.

The From line is whatever the sender typed. The headers tell you who actually delivered it, and that's who you report it to.

The short version Open the full headers. Find the Received line just below the one your own mail provider added, and look at the DKIM signatures. Together they tell you which company's servers sent the email. Report it to that company's abuse desk.

Step 1: Open the full headers

You'll get a wall of text above the message. It looks worse than it is. You only need a few lines.

Step 2: Follow the Received lines

Every mail server that handles an email adds a Received line to the top. So they read like a stack, newest on top:

For example, Received: from a8-19.smtp-out.amazonses.com just below your provider's lines means Amazon SES delivered it. Received: from ... mta.salesforce.com means Salesforce did.

Step 3: Check SPF, DKIM and DMARC

Your provider checks these and writes the results in an Authentication-Results line. They answer: was this email really allowed to come from where it says?

SPF
Whether the sending server is on the list of servers allowed to send for the domain in the return address. spf=pass means yes.
DKIM
A digital signature added by whoever sent the email. The d= part of the signature names the domain that signed it. This is one of the best clues you get: a signature from amazonses.com, sendgrid.net or mcsv.net names the service, and a second signature usually names the sender's own domain.
DMARC
Whether SPF or DKIM passed for the domain actually shown in the From line. dmarc=fail on a message from a big-name domain is a red flag for forgery. On cold spam it often just means the sender pushed a Gmail or Outlook address through a bulk mailer that isn't allowed to send for it.

Step 4: Recognize the sending service

Most spam goes through a handful of big services. Each leaves fingerprints in the headers:

Salesforce
mta.salesforce.com in a Received line, and X-SFDC- headers. How to report Salesforce spam.
Amazon SES
smtp-out.amazonses.com, a Feedback-ID ending in AmazonSES, and a DKIM signature from amazonses.com. How to report Amazon SES spam.
SendGrid
sendgrid.net in the Received lines or the DKIM signature.
Mailchimp
mcsv.net or mcdlv.net.
HubSpot
hubspotemail.net.
Brevo (formerly Sendinblue)
brevo or sendinblue.com.
Microsoft 365
outbound.protection.outlook.com. A business sending from its own Microsoft account; report it to Microsoft.
Google Workspace or Gmail
A mail-...google.com server, DKIM from gmail.com or the sender's domain signed by Google.

If you can't find any of these, the server name in the Received line and its IP address belong to some hosting company. Look the IP up on a WHOIS service to find out which one, and report it to that company's abuse address.

Step 5: Report it to the right place

Some services act on reports and some don't. Here's my scoreboard of who actually does something.