How to Find Full Email Headers (Gmail, Outlook, Apple Mail & More)

If you are dealing with a suspicious email, tracking down a phishing attempt, or wondering why a message took three days to arrive, standard email views won’t give you the answers. You need to look under the hood at the email header.

Think of an email header as a digital packing slip. It contains the technical routing data, server hops, and security authentication marks (SPF, DKIM, and DMARC) that prove whether an email is legitimate or spoofed.

Because every email provider hides this technical data differently, here is exactly how to grab the full headers on whatever platform you use.

Webmail Services

Gmail

  1. Open the email.
  2. Click the three vertical dots next to the Reply button.
  3. Click Show original.
  4. A new tab will open with the raw text. Click Copy to clipboard to grab all of it.

Outlook.com / Office 365 (Web Browser)

  1. Open the email.
  2. Click the three horizontal dots (More actions) in the top-right corner of the message pane.
  3. Hover over View, then select View message details.
  4. A window will pop up containing the header text. Select all and copy it.

Yahoo Mail

  1. Open the email.
  2. Look at the top toolbar above the email content and click the three horizontal dots icon.
  3. Click View raw message.
  4. The full header code will open in a clean, scrollable window for you to copy.

Desktop Email Clients

Microsoft Outlook (Classic Windows Desktop App)

  1. Double-click the email to open it in its own separate window.
  2. Click File in the top-left menu.
  3. Click the Properties button at the bottom of the screen.
  4. Look for the Internet headers text box at the very bottom of the popup window. Click inside, press Ctrl + A to select all, and copy it.

Apple Mail (macOS)

  1. Click on the email in your inbox.
  2. Go to the top Mac menu bar and click View.
  3. Hover over Message, then choose Raw Source.

Pro tip: You can also just hit Option + Command + U on your keyboard.

Mozilla Thunderbird

  1. Open the message.
  2. On the right side of the sender information panel, click the More button.
  3. Select View Source from the drop-down menu.

What are you actually looking for in there?

Raw header data looks like an absolute mess of code. If you are trying to troubleshoot or spot a scam, don't read the whole thing line-by-line. Instead, press Ctrl + F (or Cmd + F) and look for these key markers:

  • Authentication-Results: Look closely at this section to see if the email passed SPF, DKIM, and DMARC. If you see spf=fail or dmarc=fail, someone is likely spoofing the sender's domain.
  • Received: These are the server stops the email made on its way to you. Read them from bottom to top to track the exact timeline and see which server caused a delivery delay.
  • Return-Path: Scammers often change the visible "From" address, but they rarely mask the Return-Path. This line shows where bounce-back emails actually go, revealing the true sending account.

If you don't want to dig through the code yourself, copy the whole block of text and paste it into a free public parser like the Google Workspace Toolbox Messageheader or MXToolbox. They will instantly map out the server timeline and security flags in a clean visual layout.

Recommended web hosting option: SiteGround — fast performance, excellent customer support, and easy WordPress management.

Use promo code 1d0llar at NameSilo to get $1 off your domain.

💐