How to read email headers to find who really sent it.
The From line is whatever the sender typed. The headers tell you who actually delivered it, and that's who you report it to.
The short version
Open the full headers. Find the Received line just below the one your own mail provider added, and look at the
DKIM signatures. Together they tell you which company's servers sent the email. Report it to that company's abuse desk.
Step 1: Open the full headers
Gmail: open the email, click the three dots next to Reply, then Show original.
Outlook (desktop): open the email, then File, Properties, and look in Internet headers.
Outlook on the web: the three dots, then View, then View message source.
Apple Mail:View, then Message, then All Headers.
Yahoo Mail: the three dots, then View raw message.
Thunderbird:View, then Message Source.
You'll get a wall of text above the message. It looks worse than it is. You only need a few lines.
Step 2: Follow the Received lines
Every mail server that handles an email adds a Received line to the top. So they read like a stack, newest on top:
The top one or two were added by your own mail provider when it accepted the message.
The next one down is the important one: it says which server handed the email to your provider. That's the sender's mail service.
Lines further down were added before that. Spammers can fake those, so don't trust anything below the first server that isn't yours.
For example, Received: from a8-19.smtp-out.amazonses.com just below your provider's lines means Amazon SES delivered it. Received: from ... mta.salesforce.com means Salesforce did.
Step 3: Check SPF, DKIM and DMARC
Your provider checks these and writes the results in an Authentication-Results line. They answer: was this email really allowed to come from where it says?
SPF
Whether the sending server is on the list of servers allowed to send for the domain in the return address. spf=pass means yes.
DKIM
A digital signature added by whoever sent the email. The d= part of the signature names the domain that signed it. This is one of the best clues you get: a signature from amazonses.com, sendgrid.net or mcsv.net names the service, and a second signature usually names the sender's own domain.
DMARC
Whether SPF or DKIM passed for the domain actually shown in the From line. dmarc=fail on a message from a big-name domain is a red flag for forgery. On cold spam it often just means the sender pushed a Gmail or Outlook address through a bulk mailer that isn't allowed to send for it.
Step 4: Recognize the sending service
Most spam goes through a handful of big services. Each leaves fingerprints in the headers:
smtp-out.amazonses.com, a Feedback-ID ending in AmazonSES, and a DKIM signature from amazonses.com. How to report Amazon SES spam.
SendGrid
sendgrid.net in the Received lines or the DKIM signature.
Mailchimp
mcsv.net or mcdlv.net.
HubSpot
hubspotemail.net.
Brevo (formerly Sendinblue)
brevo or sendinblue.com.
Microsoft 365
outbound.protection.outlook.com. A business sending from its own Microsoft account; report it to Microsoft.
Google Workspace or Gmail
A mail-...google.com server, DKIM from gmail.com or the sender's domain signed by Google.
If you can't find any of these, the server name in the Received line and its IP address belong to some hosting company. Look the IP up on a WHOIS service to find out which one, and report it to that company's abuse address.
Step 5: Report it to the right place
Report to the delivering service, not just the sender. The sender already knows they're spamming. The service can shut the account off.
Paste the full headers into the report, unedited. If you want to hide your own address, say so, but leave the rest alone.
Keep the case numbers they send back, and cite them if the sender comes back.