Demystifying Email Headers: How to Spot a Phishing Attempt Using IP Lookups
Phishing attempts bypass traditional email filters every single day. While the visual body of an email might template a legitimate brand with perfect precision, the underlying raw metadata keeps a forensic ledger of its actual origin.
To protect your business from cyber fraud, you must look past styled graphics and inspect raw email headers. In this definitive guide, we will break down the complex structure of SMTP mail metadata, teach you how to follow the 'Received' header trail, and explain how to run DNS lookups to verify the real identity of any sender.
1. Accessing Raw Headers Across Popular Email Clients
Before tracing a sender's IP, you must extract the raw header metadata. This hidden block of text precedes the HTML load of every message. In Gmail, you can access this by clicking the three-dot options menu and selecting 'Show Original'. In Microsoft Outlook, select 'File', 'Properties', and view the 'Internet Headers' dialog. This outputs a dense block of key-value fields containing the message's routing history, security signatures, and transmission stamps.
This block contains important routing details that cannot be hidden by the sender. While a standard visual reader only displays the 'From' field, raw headers register the exact path the message took across the web.
2. Navigating the 'Received' Hop Trail Chronologically
The most important field in any email header is the 'Received' line. Every mail server that processes a message appends its own 'Received' statement at the very top of this metadata block. This means reading raw headers is chronological from bottom to top: the topmost 'Received' header represents the final delivery point, while the bottom-most represents the initial sender.
Inspect the final 'Received' line at the bottom of the list. It contains the sender's hostname, the server IP, and a timestamp. If a message claims to come from 'support@yourbank.com' but the bottom-most 'Received' header lists a residential broadband IP or a foreign virtual server, the message is a spoofed phishing attempt.
3. Decoding SPF, DKIM, and DMARC Verification Failures
Because manual metadata checks can be slow, modern receiving servers run automatic security tests on arrival. The results of these tests are recorded directly in the 'Authentication-Results' header field.
When reading this field, verify the SPF status registers as 'pass' with a matching sender domain. Check the DKIM signature status, which cryptographically confirms the email content wasn't altered in transit. Finally, review the DMARC status. If any of these checks return 'fail', 'softfail', or 'none', use extreme caution—these are major indicators of a spoofed or altered message.
4. Using Reverse DNS and Geolocation Lookups to Unmask Scams
Once you locate the sender's IP, run a reverse DNS (PTR) check and check the IP location. A legitimate billing email from a global brand should route through their official corporate servers. If your reverse DNS check points to an unfamiliar home connection, a shared hosting platform, or a completely different country of origin, the message is highly likely a phishing scam.
Ensure your organization knows how to quickly review this forensic data. Taking a few seconds to verify routing details can prevent credential leaks and keep your business secure.
Lookup History
Your lookup logs appear clean.
Professional Integrity
The WHOIS Lookup system provides advanced domain intelligence by combining authoritative DNS checking with AI verification to evaluate risks in real-time.
- Instant registrar audits
- Live active zone maps
- Threat scoring classification