Back to blog
Infrastructure

How to View Email Headers in Gmail

how to view email headers is the fastest way to see whether SPF, DKIM, and DMARC passed on a real message, not what your DNS panel claims.

ZeroHook
ZeroHook Team
Security Analysts
Oct 7, 2026~3 min read
How to View Email Headers in Gmail
how to view email headers in Gmail means opening Show original on a delivered message, because that raw view is where Authentication-Results shows spf=, dkim=, and dmarc= for your domain.

Gmail (Web and Mobile)

1

Open the message in Gmail (inbox or Spam). Click the three-dot menu → Show original. A new tab opens with the full MIME source.

2

Use Find (Ctrl+F / Cmd+F) and search for Authentication-Results. On mail received at Gmail you usually see a block from google.com.

3

Read the three legs on one line or nearby lines:

spf=pass (or fail)

dkim=pass (or fail)

dmarc=pass (or fail)

4

Note the domains. SPF often shows which domain was authorized. DKIM shows d=yourdomain.com on a aligned signature. DMARC fails when neither leg aligns with the visible From: address.

5

On the Gmail app: open the message → tap the three dots → Show original (wording may vary by app version). Same search for Authentication-Results.

Outlook on the Web and Microsoft 365

1

Open the message in Outlook on the web. Click the three dots on the message toolbar → View → View message details (or View message source, depending on build).

2

Search for Authentication-Results or Received-SPF. Microsoft may list spf= and dkim= in separate header blocks.

3

For a message you sent from M365, you want spf=pass and dkim=pass with domains that match your From: address. Forwarded mail often breaks SPF while DKIM may survive.

Apple Mail (macOS)

1

Open the message. Menu View → Message → Raw Source (or All Headers).

2

Search Authentication-Results or dkim=pass. Apple Mail does not rewrite headers; you see what the receiving server added.

What good looks like on a test you sent yourself

Send from your work address to a personal Gmail. Show original should show spf=pass, dkim=pass, and dmarc=pass for the same brand domain in From:. One leg passing while dmarc=fail usually means alignment, not a missing DNS record.

Spam folder vs inbox

Headers tell you why a message landed in Spam, not whether your marketing tool dashboard is optimistic. Compare one inbox message and one spam message side by side. The diff in Authentication-Results beats any green check in an ESP UI.

Do not paste secrets

Headers include routing IPs, Message-IDs, and sometimes internal hostnames. Redact before you post in a ticket or public thread.

Pro tip

Screenshot Authentication-Results only when you share with a vendor. Full raw source leaks more than you need.

Frequently Asked Questions

Key takeaways

1

Gmail Show original is the default path for how to view email headers when you troubleshoot deliverability.

2

Search Authentication-Results first; read spf=, dkim=, and dmarc= together.

3

Compare inbox vs spam copies of the same campaign template.

4

Headers reflect one message path; DNS tools reflect published records. Use both.

5

Redact raw headers before sharing outside your team.

After you read headers on a test message, confirm DNS matches at zerohook.org/dns-health-check before you change SPF or DMARC again.

Share this analysis

Help others discover this content

Fix DNS before the next audit
Provider-specific copy-paste fixes for Cloudflare, Route53, GoDaddy, and more.
Start free scan

More from our blog