Decoding phishing email headers to uncover the true sender

Phishing remains one of the most reported cybercrime categories in Australia, with the ACCC's Scamwatch logging tens of thousands of complaints annually. Many of these fraudulent messages pretend to be urgent notices from major banks, Australia Post, or government services such as myGov. Understanding how to dissect a suspicious email is an essential skill for anyone who manages an inbox in Sydney, Brisbane, or Perth.

Hidden inside every email lies a layer of metadata known as headers. These headers document the servers that handled the message, the authentication checks that were performed, and the timestamps marking each stop along the route. While a scammer can craft a convincing body with familiar logos and persuasive language, the headers frequently expose the real origin through technical inconsistencies.

Three core protocols work behind the scenes to verify the legitimacy of a sender: SPF, DKIM, and DMARC. When these are aligned and correctly configured, receiving mail servers can confirm that a message actually came from the domain it claims to represent. When the checks fail or are missing entirely, the message carries strong hallmarks of fraud.

Analysing these clues does not demand advanced expertise, just a methodical approach and the right supporting tools. A free service such as Trusted Sender Score can complement manual header inspection by confirming the standing of the domains and infrastructure connected to the message.

Gathering the full email header from your client

Before you can analyse anything, you need the complete raw header. In Gmail, open the message, click the three vertical dots next to the reply arrow, and choose "Show original". In Outlook on the web, select the message, click the three dots, and choose "View message source". Apple Mail users on macOS can select the message and go to "View > Message > Raw Source".

If you read your email through an Australian provider like Telstra or Optus, the webmail interface will have a similar option, usually behind a "More actions" button. Save the full output to a text file so you can scroll through it without losing formatting. The header always precedes the visible body of the email, so a long block of text above the message content is exactly what you need.

Tracing the path through the received chain

The "Received" field appears multiple times in any header, once for every server that processed the email. To trace the journey, read the chain from bottom to top, starting with the oldest entry. The bottom-most "Received" line usually reveals the originating IP address and the sending server's identity.

Copy that IP address and run it through a free geolocation service. If a message claims to come from a Melbourne law firm but the originating IP sits in a data centre overseas, that mismatch is a major red flag. Time stamps often use Coordinated Universal Time, so convert them to Australian Eastern Standard Time to verify the claimed sending window.

Interpreting SPF, DKIM, and DMARC results

Look for the "Authentication-Results" header, which summarises the outcome of each protocol. SPF will show as "pass", "softfail", "fail", or "none". A "pass" means the sending server was authorised by the domain's SPF record. DKIM produces a similar result based on a digital signature, while DMARC ties the two together by checking alignment between the visible "From" address and the authenticated domain.

When DMARC fails, the receiving server should ideally reject or quarantine the message. If the email reaches your inbox despite a "fail" result, the spoofed organisation has a misconfigured policy. This is common among smaller Australian businesses that have not yet adopted strict DMARC rules, which is why scammers frequently target them.

Spotting domain spoofing and lookalike domains

Scammers often register domains that mimic legitimate Australian businesses. Watch for subtle changes such as a missing letter, a swapped character, or a different country code top-level domain. A message claiming to be from "commbank.com.au" might actually originate from "commbank-au.com" or "commbank.com".

The display name can also be manipulated independently of the actual email address. An attacker can set the name to "NAB Fraud Team" while sending from a random Gmail account. Always compare the friendly name against the underlying address, and hover over any links to confirm they point to the genuine domain before clicking.

Cross-referencing domains and IPs with reputation data

Once you have isolated the suspicious domain and IP, it pays to check their history against independent databases. Reputation tools aggregate data from spam traps, blocklists, and historical sending patterns. This is where you can verify domain reputation and see if the infrastructure has been flagged elsewhere.

For a security team in a Sydney-based enterprise, bulk domain checking can reveal whether the same infrastructure has been used in other campaigns. Developer tools and APIs also allow automated lookups, which is helpful when triaging dozens of reports after a wave of phishing hits an Australian workplace.

Reporting and preserving the evidence

After completing your analysis, report the phishing attempt to the Australian Cyber Security Centre through ReportCyber, and lodge a complaint with Scamwatch. If the email impersonates a specific Australian entity, such as a major bank or Australia Post, forward the full message with headers to the organisation's dedicated abuse address.

Keep a copy of the raw header in a secure location, as law enforcement and the impersonated company may request it during their investigation. Maintaining a small log of incidents, including timestamps converted to local AEDT or AEST, helps build a pattern that can protect your colleagues, family, or customers from the next wave of attacks.