The first affair you practise when you hear that electronic mail notification is check the sender, right? It is the quickest way to figure out who the e-mail is from, likewise every bit the probable content.

But did y'all know each email comes with a lot more than information than what appears in most email clients? At that place's a host of information about the sender included in the email header—information you lot can use to trace the email dorsum to the source.

Here's how to trace that email dorsum to where it came from and why you might want to.

Why Trace an E-mail Accost?

Before learning how to trace an email address, let's consider why you would exercise it in the first place.

In this day and historic period, malicious emails are all too frequent. Scams, spam, malware, and phishing emails are a mutual inbox sight. If yous trace an e-mail dorsum to its source, you have a slight chance of discovering who (or where!) the email comes from.

In other cases, you can trace the origin of an e-mail to block a persistent source of spam or abusive content, permanently removing information technology from your inbox; server administrators trace emails for the same reason.

(If you want to foreclose your own email identity from existence revealed, acquire to send completely anonymous emails.)

How to Trace an Electronic mail Address

Yous can trace an electronic mail accost to its sender by looking at the full email header. The electronic mail header contains routing information and electronic mail metadata—information you don't unremarkably care about. Only that information is vital to tracing the source of the email.

Most e-mail clients don't brandish the full email header equally standard because it is full of technical information and somewhat useless to an untrained eye. Nonetheless, most electronic mail clients do offering a way of checking out the total email header. You but need to know where to expect, every bit well equally what you're looking at.

  • Gmail Full Email Header: Open your Gmail business relationship, then open the email y'all want to trace. Select the drop-down menu in the acme-right corner, and then Bear witness original from the carte.
  • Outlook Full Email Header: Double-click the email you desire to trace, the head to File > Backdrop. The information appears in the internet headers.
  • Apple tree Mail Total Email Header: Open the electronic mail you lot wish to trace, and then head to View > Message > Raw Source.

Of class, there are countless electronic mail clients. A quick internet search will reveal how to find your full email header in your client of choice. One time yous take the full email header open, you'll empathize what I meant by "full of technical information."

Understanding the Data in a Full Email Header

It looks like a lot of information. Nonetheless, consider the following: y'all read the electronic mail header chronologically, from bottom to pinnacle (i.e., oldest information at the bottom), and that each new server the e-mail travels through adds Received to the header.

Check out this sample email header taken from my MakeUseOf Gmail account:

There's a lot of information. Let'southward break it downward. First, empathise what each line means (reading from bottom to top).

  • Reply-To: The e-mail address you send your response to.
  • From: Displays the message sender; it is piece of cake to forge.
  • Content-type: Tells your browser or email customer how to interpret the content of the email. The most common character sets are UTF-8 (seen in the example) and ISO-8859-1.
  • MIME-Version: Declares the email format standard in utilise. The MIME-Version is typically "one.0."
  • Bailiwick: The subject of the email contents.
  • To: The intended recipients of the email; may show other addresses.
  • DKIM-Signature: DomainKeys Identified Gail authenticates the domain the e-mail was sent from and should protect confronting email spoofing and sender fraud.
  • Received: The "Received" line lists each server that the electronic mail travels through before hitting your inbox. You lot read "Received" lines from lesser to top; the lesser-most line is the originator.
  • Authentication-Results: Contains a record of the authentication checks carried out; can contain more than one authentication method.
  • Received-SPF: The Southender Policy Framework (SPF) forms part of the email authentication process that stops sender address forgery.
  • Return-Path: The location where non-transport or bounce letters end upwardly.
  • ARC-Hallmark-Results: The Authenticated Receive Chain is another authentication standard; ARC verifies the identities of the e-mail intermediaries and servers that forward your bulletin to its last destination.
  • ARC-Message-Signature: The signature takes a snapshot of the message header information for validation, similar to DKIM.
  • ARC-Seal: "Seals" the ARC authentication results and the bulletin signature, verifying their contents; like to DKIM.
  • Ten-Received: Differs from "Received" in that it is considered non-standard; that is to say, it might not be a permanent address, such every bit a mail transfer agent or Gmail SMTP server. (See below.)
  • X-Google-Smtp-Source: Shows the email transferring using a Gmail SMTP server.
  • Delivered-To: The final recipient of the email in this header.

You lot don't have to sympathise what all of these things mean to trace an email. But if you larn to look through the email header, you lot can quickly begin to trace the email sender.

Tracing the Original Sender of an Email

To trace the IP accost of the original e-mail sender, caput to the commencement Received in the total email header. Alongside the kickoff Received line is the IP address of the server that sent the electronic mail. Sometimes, this appears equally X-Originating-IP or Original-IP.

Notice the IP address, so head to MX Toolbox. Enter the IP address in the box, modify the search type to Reverse Lookup using the drop-downwardly menu, then hit Enter. The search results volition display a diverseness of information relating to the sending server.

Unless the originating IP accost is i of the millions of private IP addresses. In that instance, you will meet the following message:

The following IP ranges are private:

  • 0.0.0-10.255.255.255
  • 16.00-172.31.255.255
  • 168.0.0-192.168.255.255
  • 0.0.0-239.255.255.255

IP address lookups for those ranges will non return whatever results.

Of course, at that place are some handy tools out there that automate this process for you. It is handy to larn about full email headers and their contents, but sometimes you lot demand quick information.

Check out the following header analyzers:

  • GSuite Toolbox Messageheader
  • MX Toolbox Email Header Analyzer
  • IP-Address Email Header Trace (email header analyzer + IP accost tracer)

The results don't e'er lucifer upwards, though. In the beneath example, I know that the sender is nowhere almost the alleged location, stated as in the eye of a reservoir most Wichita.

In that, your success with tracing an e-mail volition vary depending on the electronic mail provider of the sender. For example, if you lot're trying to trace an email sent from a Gmail account, you lot'll but find out the location of the last Google server that candy your email—not the IP address of the original sender.

Tin can You Really Trace an IP Address from an Email?

At that place are instances where tracing an IP address through the e-mail header is useful. A particularly irritating spammer, perhaps, or the source of regular phishing emails.

Certain emails will only come from sure locations; your PayPal emails won't originate in China, for instance. In that, tracing the origin of an email isn't a precise scientific discipline, at least not with easily attainable tools.

7 Common Electronic mail Security Protocols Explained

How exercise ISPs and webmail services protect email users? Here's how the seven email security protocols keep your messages safe.

Read Next

Virtually The Author