How to Collect Email Headers for SPF, DKIM, and DMARC Review
Message headers show what actually happened when a mailbox provider received your email. They are the fastest way to verify SPF, DKIM, DMARC, return-path, signing domain, and sender alignment without sharing a mailbox password.
Quick answer: Collect one recent header from each active sender: your main mailbox platform, CRM or marketing platform, outbound tool, and transactional email service.
Want this handled for you?The 48-hour audit checks the full sender setup and gives you a prioritized repair plan.
Before you change anything
- Do not forward the message. Forwarding changes the evidence and can hide the original authentication result.
- Use a message that was actually delivered, spam-foldered, rejected, or flagged by the recipient system.
- Label each header by sender platform before making DNS changes.
Step-by-step repair process
- Pick the sender platform. Start with Google Workspace or Microsoft 365, then repeat for HubSpot, Klaviyo, Mailchimp, SendGrid, Apollo, Instantly, Smartlead, or any other tool sending as your domain.
- Open the original message. In Gmail, use “Show original.” In Outlook or Microsoft 365, use the message properties or view message source option.
- Copy the full header block. Include the lines for Authentication-Results, Received-SPF, DKIM-Signature, Return-Path, From, Reply-To, and every Received line.
- Save the business context. Note whether the message was a normal reply, newsletter, cold outreach, invoice, password reset, or transactional notice.
- Look for alignment evidence. Compare the visible From domain against the SPF return-path domain and the DKIM d= signing domain.
- Do not edit DNS from one header. One message can prove a sender exists, but a safe repair plan needs headers from every active sending path.
Common mistakes to avoid
- Using only a successful Gmail-to-Gmail message and assuming every marketing or CRM sender is also aligned.
- Copying only the visible From address instead of the full authentication header.
- Changing SPF or DMARC before identifying which platform generated the failing message.
Related repair guides
Reference points
These are technical reference points, not a substitute for checking your real message headers and sender inventory.
Not sure which fix comes first?Send the domain and sender tools through the audit. We will prioritize the repair path.