How to Collect Email Headers for SPF, DKIM, and DMARC Review

Message headers show what actually happened when a mailbox provider received your email. They are the fastest way to verify SPF, DKIM, DMARC, return-path, signing domain, and sender alignment without sharing a mailbox password.

Quick answer: Collect one recent header from each active sender: your main mailbox platform, CRM or marketing platform, outbound tool, and transactional email service.
Want this handled for you?The 48-hour audit checks the full sender setup and gives you a prioritized repair plan.

Start Audit – $399

Before you change anything

  • Do not forward the message. Forwarding changes the evidence and can hide the original authentication result.
  • Use a message that was actually delivered, spam-foldered, rejected, or flagged by the recipient system.
  • Label each header by sender platform before making DNS changes.

Step-by-step repair process

  1. Pick the sender platform. Start with Google Workspace or Microsoft 365, then repeat for HubSpot, Klaviyo, Mailchimp, SendGrid, Apollo, Instantly, Smartlead, or any other tool sending as your domain.
  2. Open the original message. In Gmail, use “Show original.” In Outlook or Microsoft 365, use the message properties or view message source option.
  3. Copy the full header block. Include the lines for Authentication-Results, Received-SPF, DKIM-Signature, Return-Path, From, Reply-To, and every Received line.
  4. Save the business context. Note whether the message was a normal reply, newsletter, cold outreach, invoice, password reset, or transactional notice.
  5. Look for alignment evidence. Compare the visible From domain against the SPF return-path domain and the DKIM d= signing domain.
  6. Do not edit DNS from one header. One message can prove a sender exists, but a safe repair plan needs headers from every active sending path.

Common mistakes to avoid

  • Using only a successful Gmail-to-Gmail message and assuming every marketing or CRM sender is also aligned.
  • Copying only the visible From address instead of the full authentication header.
  • Changing SPF or DMARC before identifying which platform generated the failing message.

Related repair guides

Reference points

These are technical reference points, not a substitute for checking your real message headers and sender inventory.

Not sure which fix comes first?Send the domain and sender tools through the audit. We will prioritize the repair path.

Start Audit – $399