Back to all articles
Technical Guide

Reading Raw Email Headers in Outlook Web App: A Step‑by‑Step Guide

NT
The Network Tools TeamSecurity Research
Published
Read Time1 min

When a message lands in your inbox, most of its journey is hidden from view. The raw email header is the “passport” that records every hop, verification check, and routing decision. Knowing how to read it in the Outlook Web App (OWA) can help you spot spoofed senders, troubleshoot delivery delays, and verify DKIM/SPF authentication. Below is a practical, no‑fluff walkthrough—plus a quick tip on how The Network Tools can take your analysis a step further.


Why Email Headers Matter

Reason What It Looks Like in the Header Real‑World Impact
Authentication Authentication-Results: spf=pass; dkim=pass; dmarc=pass Confirms the sender isn’t a phisher.
Routing Path Received: from mail.example.com (mail.example.com. [203.0.113.5]) Shows each server that touched the message.
Spam Scoring X-Spam-Score: 5.2 Helps you understand why a message landed in Junk.
Debugging Delays Multiple Received lines with timestamps Pinpoints the server that introduced latency.

Think of the header as a forensic report: the more you can read, the easier it is to reconstruct what happened before the email reached you.


Where to Find Raw Headers in Outlook Web App

  1. Open the message you want to inspect.
  2. Click the three‑dot menu (⋯) in the top‑right corner of the reading pane.
  3. Choose “View” → “View message source.”
  4. A new browser tab opens, displaying the full RFC‑822 source—including all header fields and the body in plain text.

Tip: If you’re on a shared or public computer, close the source tab immediately after copying what you need to avoid leaving sensitive data exposed.


How to Copy and Interpret Common Header Fields

1. Received: lines – the breadcrumb trail

Received: from mail-out.example.com (mail-out.example.com. [203.0.113.5])
        by outlook.office365.com with ESMTPS id 3M4K7L9X0
        for <[email protected]>; Tue, 1 Oct 2026 14:32:10 +0000
  • First server (mail-out.example.com) is the origin.
  • Second server (outlook.office365.com) is the first Microsoft hop.
  • Timestamp tells you when each hop occurred.

If you see a Received: entry from an IP you don’t recognize, that could be a sign of a compromised relay.

2. From: vs. Reply‑To:

From: "Acme Support" <[email protected]>
Reply-To: "Acme Sales" <[email protected]>

A mismatch may indicate a phishing attempt—especially if the Reply‑To domain differs from the From domain.

3. Authentication results

Authentication-Results: outlook.com;
        spf=pass smtp.mailfrom=acme.com;
        dkim=pass header.d=acme.com;
        dmarc=pass (p=none sp=none) header.from=acme.com
  • SPF pass means the sending IP is authorized for acme.com.
  • DKIM pass confirms the message wasn’t altered in transit.
  • DMARC pass ties SPF and DKIM together, giving you confidence the sender is legitimate.

4. Spam and security headers

X-Spam-Status: No, score=-0.1 required=5.0
X-Microsoft-Antispam-Message-Info: 0
X-Microsoft-Antispam-PRVS: 1

Negative scores usually mean the message is clean. A high X-Spam-Score is a red flag.


Using The Network Tools for Deeper Analysis

Reading the header tells you what happened; the next step is to verify why it happened.

  • DNS Lookups: Paste the domain from the Received: line into The Network Tools’ DNS checker to see its current A, MX, and TXT records.
  • MX Verification: Confirm that the mail server listed (mail-out.example.com) is actually authorized to send for the domain.
  • WHOIS Lookup: Use the IP address from a Received: line to see the owning organization—useful for spotting rogue cloud servers.

These diagnostics are especially handy when you encounter a header that references a new or unexpected sub‑domain. A quick lookup can confirm whether the domain is legitimate or newly registered for malicious purposes.


Common Issues & Troubleshooting

Symptom Likely Header Clue Fix
Email lands in Junk despite being from a trusted sender X-Spam-Score unusually high, or missing DKIM signature Ask the sender to enable DKIM; add the sender to your safe‑senders list.
Delayed delivery (hours) Large gap between timestamps on consecutive Received: lines Identify the server with the biggest gap; contact that provider’s support.
Phishing attempt From: address differs from domain in DKIM/SPF results Report to your IT security team; block the offending IP using the Received: IP.
Undeliverable bounce Diagnostic-Code: smtp; 550 5.1.1 in the bounce message Verify the recipient address; check DNS MX records for the destination domain.

Quick Reference Cheat Sheet

Header What to Look For Red Flag
Received: Server chain, timestamps, IPs Unknown IP, large time gaps
From: / Reply‑To: Domain consistency Mismatched domains
Authentication-Results SPF/DKIM/DMARC status Any “fail” or “neutral”
X-Spam-Score Numeric score >5.0 (or your organization’s threshold)
DKIM-Signature d= domain matches From: Mismatch or missing signature

Wrap‑Up

Reading raw email headers in Outlook Web App isn’t just a curiosity—it’s a frontline defense against spoofing, spam, and delivery headaches. By mastering the “passport” of each message, you gain visibility into the hidden path an email travels, can verify authentication, and quickly pinpoint where things went wrong.

Remember: the header gives you the what and when; tools like The Network Tools provide the why by letting you validate DNS, MX, and WHOIS data in seconds. Keep this workflow in your toolbox, and you’ll troubleshoot email issues with the confidence of a seasoned network detective.


Ready to dig deeper? Try The Network Tools’ free DNS and MX lookup suite right after you’ve copied an IP or domain from your header. It’s the fastest way to confirm whether a server is legit or a potential threat.

You might also need

Keep troubleshooting with these related free tools.