How to Trace Where an Email Really Came From

The sender name on an email is trivial to fake. How to read email headers to find the real origin, tell spoofing from a genuine sender, and identify who is actually behind a message.

By the StoryCheck Team7 min read

The name on an email means nothing. "PayPal Security" or "Mom" in the From field is just text the sender typed, and faking it takes seconds. What is much harder to fake is the technical trail every email carries in its headers: the real sending server, the authentication results, and the path the message actually traveled. Reading those tells you whether a message is genuinely from who it claims, and often points at the real origin.

A tablet on a desk showing a privacy protection screen
The sender name is free text. The headers are where the truth sits.

Open the full headers

1

Gmail

Open the email, click the three-dot menu, choose "Show original".

2

Outlook

Open the email, File or the three-dot menu, then "View message source" / "Properties".

3

Apple Mail

Select the email, View menu, Message, then "All Headers" or "Raw Source".

4

What you are looking for

The Return-Path, the Received lines, and the Authentication-Results block.

Read the three things that matter

First, Authentication-Results: look for SPF, DKIM, and DMARC. If they say "pass", the message genuinely came from a server authorized by the domain it claims. If SPF or DMARC says "fail", the sender is very likely spoofing that domain. Second, the Return-Path and the real From domain: a message claiming to be PayPal whose Return-Path is a random gmail or a lookalike domain is a fake. Third, the bottom-most Received line shows the originating server, often revealing the true sending service or region.

When the headers check out but you still don't know the person

Sometimes the email is authentically from the address it claims, and the question is simply who owns that address. That is where header analysis ends and a reverse email lookup begins: it takes the confirmed-real address and returns the likely owner, linked accounts, and any connected phone number. StoryCheck runs the address privately and the sender is never notified.

The honest limits

Headers can reveal the sending server without revealing the human, especially when a message is sent through a big mail provider whose servers everyone shares. Skilled senders using their own infrastructure can also obscure the trail. Headers are excellent at answering "is this spoofed?" and only sometimes answer "who exactly is this?", which is why the address itself, run through a lookup, is the other half of the job.

Run a private check on any phone number

Get a 60 second report with possible owner, line type, location signals, and risk indicators. The phone owner is not notified.

Run a check

Frequently asked questions

Can email headers tell me exactly who sent a message?

They reliably tell you whether the sender is spoofing the claimed domain and reveal the sending server. They often do not reveal the individual, especially for mail sent through large shared providers. To identify the owner of a confirmed-real address, use a reverse email lookup.

How do I know if an email is spoofed?

Check the Authentication-Results header for SPF, DKIM, and DMARC. A DMARC or SPF "fail", or a Return-Path domain that does not match the claimed sender, means the message is very likely spoofed.

The From name looks right. Does that mean it's safe?

No. The From name is free text anyone can type. Only the domain after the @ and the authentication results matter. Always check those before trusting a message.

Related articles

Check the number. Know more.

Run a private 60 second report. The phone owner will not be notified.

Start your check
How to Trace Where an Email Really Came From 路 StoryCheck