TetraHost Bangladesh

The Official Company Blog

  • Home
  • Blog
  • Home
  • About Us
  • Contact Us

TetraHost Bangladesh

The Official Company Blog

  • Home
  • Blog
  • Home
  • About Us
  • Contact Us

Tag Archives: Email Header

06 Oct

How to Check an Email Header and Verify an Email Is Legitimate

Receiving an email that looks like it came from your hosting provider, bank, Google, Microsoft, or another trusted service does not always mean it is genuine.

Phishing emails can be designed to look almost identical to legitimate emails. They may ask you to verify your account, update your password, restore your mailbox, make a payment, or click a button to avoid account suspension.

Before clicking any link or providing your password, it is a good practice to check the email source or header first.

Why Should You Check an Email Header?

The name and email address shown in your inbox can sometimes be misleading. Attackers can use spoofing and other techniques to make an email appear to come from a trusted person or company.

The email header contains additional technical information about how the message was sent and which servers handled it.

You do not need to understand every line of a header. When checking a suspicious email, look for information such as:

  • The actual sender address
  • The sending server or IP address
  • SPF authentication results
  • DKIM authentication results
  • DMARC results
  • The path the email took before reaching your mailbox

These details can help you determine whether an email is genuine or suspicious.

Important: Never click a link, download an attachment, or enter your password simply because an email looks legitimate.

How to Check Email Headers

The method is slightly different depending on which email service or application you use.

Gmail

  1. Open the email.
  2. Click the three dots (…) in the top-right corner of the message.
  3. Select Show original.
  4. Gmail will display the complete email header and authentication results.

You can look for SPF, DKIM, and DMARC results near the top of the page.

Gmail also provides a Download Original option if you need to save the complete message source.

Outlook / Hotmail

For Outlook on the web:

  1. Open the email.
  2. Click the three dots (…) in the message toolbar.
  3. Select View > View message details or View source, depending on the Outlook interface.
  4. Review the message headers and authentication information.

The exact wording may vary depending on whether you are using the new Outlook, Outlook.com, or another version of Microsoft Outlook.

Yahoo Mail

  1. Open the email.
  2. Click the three dots (More) menu.
  3. Select View raw message or View raw message/source, depending on the Yahoo Mail interface.
  4. Yahoo will display the complete email source.

You can search within the source for terms such as SPF, DKIM, DMARC, or Authentication-Results.

Thunderbird

Mozilla Thunderbird makes it easy to view the complete message source.

  1. Open the email.
  2. Click More or open the message menu.
  3. Select View Source.

You can also use the keyboard shortcut Ctrl + U on Windows/Linux or Command + U on macOS.

The complete message source will then be displayed.

cPanel Webmail / Roundcube

If you use cPanel Webmail with Roundcube:

  1. Open the email.
  2. Click the More option in the message toolbar.
  3. Select Show source.

Roundcube will display the complete email source, including the message headers.

If you use another webmail application provided through cPanel, the exact menu may be slightly different.

What Should You Look For?

You don’t need to understand the entire header. A few things are particularly useful.

1. Check the actual sender address

Do not rely only on the display name.

For example, an email may display:

cPanel Support

but the actual address could be:

cpanel@example-random-domain.com

If the email claims to be from your hosting provider but the actual sender domain is completely unrelated, that is a strong warning sign.

2. Check SPF, DKIM and DMARC

These are email authentication technologies that help receiving mail servers determine whether an email is authorized to use a particular domain.

You may see something similar to:

SPF: PASS
DKIM: PASS
DMARC: PASS

A passing result is generally a good sign, but it does not automatically guarantee that an email is safe.

For example, a phishing email can be sent from a legitimate but compromised or malicious domain and still pass that domain’s SPF/DKIM checks.

3. Check the links before clicking

Even if an email appears legitimate, carefully check where its links lead.

For example, an email may say:

Click here to verify your account

but the actual link could point to a completely unrelated website.

When in doubt, don’t use the link in the email. Instead, open the company’s official website manually and log in from there.

A Simple Example

Suppose you receive an email saying:

Your Webmail account will be suspended. Click “Authenticate Now” to keep your account active.

Before clicking anything:

  1. Check the actual sender address.
  2. View the email source/header.
  3. Check SPF, DKIM and DMARC results.
  4. Look at the sending domain.
  5. Check where the button or link actually leads.
  6. If anything looks suspicious, do not click it.

Instead, contact your hosting provider through its official website or open your hosting/webmail account directly.

Final Advice

Email headers are not designed to be easy for everyone to understand, but you do not need to be an email expert to use them.

When an email asks you to log in, verify your identity, change your password, make a payment, or take urgent action, take a moment to verify it first.

When in doubt, don’t click. Check the email source, verify the sender, and access the service directly through its official website.

A few seconds of checking can prevent your email account, hosting account, or other online accounts from being compromised.

aDmin Posted in How To, Security cPanel Webmail, DKIM, DMARC, Email Authentication, Email Header, Email Phishing, Email Scam, Email Security, Email Source, Email Spoofing, Email Verification, Fake Email, gmail, Hosting Security, Hotmail, Outlook, Phishing Email, Roundcube, Spam Email, SPF, Thunderbird, Webmail Security, Yahoo Mail Leave a comment

Post navigation

Fruitful theme by fruitfulcode Powered by: WordPress
↑