Email Headers Viewer

Learn how to view email headers in different versions of Microsoft Outlook for troubleshooting and analysis.

Email Headers Instructions

Outlook for Windows

How to view email headers in Microsoft Outlook for Windows desktop application

Method 1: Message Options

  1. Open the email message you want to view headers for
  2. Click on the File tab in the ribbon
  3. Click Properties (or Info then Properties)
  4. In the Properties dialog box, scroll down to find the Internet headers section
  5. Copy the headers from the text box for analysis

Method 2: Right-click Menu

  1. Right-click on the email message in your inbox
  2. Select View Source from the context menu
  3. The email source will open in Notepad or your default text editor
  4. The headers are at the top of the source code

💡 Pro Tip

You can also double-click to open the email in a new window, then use the File → Properties method for easier access.

Submit Headers for Analysis

Use your company email so our team can verify your organization before responding.

Why Email Headers Matter

Email headers record the technical story of how a message traveled from the sender to your inbox.

Every hop an email takes -- mail transfer agents, spam filters, security gateways, and the receiving mailbox -- adds metadata to the header. These entries capture timestamps, sending IP addresses, authentication results, and diagnostic flags the message collected along the way. When you review the header, you're looking at the real delivery path rather than what the sender wants you to believe.

Support teams rely on headers to trace spoofed domains, troubleshoot bounced mail, measure latency, and prove whether a message originated inside or outside the organization. Security analysts compare the envelope data against your policies to isolate compromised accounts and automatically tune spam and phishing defenses.

Saving a copy of the raw header gives you admissible evidence when coordinating with mail providers, ISPs, or law enforcement. Because email content can be forged or manipulated, the header remains the most reliable artifact for root-cause analysis.

Key Signals You'll Find in a Header

Focus on these fields when deciding if a message is trustworthy.

  • Return-Path & From:Confirms the envelope sender. If it differs from the visible display name or domain, the message may be spoofed or forwarded through a third party.
  • Received:A chronological stack (bottom to top) that lists every server that handled the email. Unexpected geographic locations, residential IPs, or servers that don't belong to your provider are red flags.
  • Message-ID & Date:Legitimate systems generate IDs that match the sender's domain. Missing IDs, timestamps way ahead or behind your time zone, or mismatched domains suggest automation or compromised accounts.
  • Authentication-Results:Shows SPF, DKIM, and DMARC verdicts. Gmail, Microsoft 365, and most gateways add this block so you can see exactly which test failed.
  • X- headers:Proprietary or additional data (spam scores, malware verdicts, routing tags) injected by secure email gateways. They help analysts understand why a filter allowed or blocked the message.

Use Headers to Spot Phishing & Spam

Correlate what your users see with the underlying transport data.

Compare the sending IPs and domains against your allow lists, vendor contacts, and reputation tools. A trusted business partner's real mail should pass SPF and DKIM using infrastructure you recognize. Anything that fails authentication or routes through consumer ISPs warrants quarantine before your staff engages.

Look for urgency cues such as "X-Priority: 1" combined with public webmail hosts. Attackers often forge high priority markers to get past busy recipients. Message traces that originate from newly registered domains or lack TLS hand-offs are also suspicious.

Headers help you prove false positives too. When a legitimate newsletter gets flagged, you can scan the delivery chain, identify the failing hop, and adjust your filters without turning off protection entirely.

Escalate a Suspicious Email

Send us the sender details, message headers, and any red flags you spotted so we can respond before the threat spreads through your tenant.

Need Another Set of Eyes on Suspicious Mail?

Our cybersecurity analysts investigate full message headers daily to trace spoofed senders, uncover forged routing, and build policies that keep your staff safe from credential phishing.

Share the suspicious email details and we'll map out the delivery path, reputation scores, and authentication failures so you know whether to quarantine a campaign or trust the sender.

Tell us how the message arrived and we'll validate SPF, DKIM, and DMARC results, then recommend isolation steps for your staff and infrastructure.