13 FOCUSED PLAYBOOKS
Message forensics
Read headers, forwarding evidence and unsubscribe fields without mistaking clues for proof.
Inspect the original raw message rather than a forwarded screenshot. Headers can contain private addresses, message identifiers and routing information, so redact a separate copy before sharing. Give the most weight to results added by your own trusted receiving infrastructure.
Open the header analyzer →Which Authentication-Results header should you trust?
Authentication-Results headers are assertions by the system that added them.
Read the playbook →DIAGNOSTIC PLAYBOOKFind an email delay using Received headers
Received timestamps can help locate the interval where a message waited, provided the relevant hops and clocks are trustworthy.
Read the playbook →DIAGNOSTIC PLAYBOOKFrom, Reply-To and Return-Path point to different places
These headers serve different purposes: visible authorship, reply destination and bounce routing.
Read the playbook →DIAGNOSTIC PLAYBOOKUse Message-ID to trace an email across systems
Message-ID can help correlate a message across logs, but it is not a cryptographic proof of origin or a guarantee of uniqueness.
Read the playbook →DIAGNOSTIC PLAYBOOKARC pass does not automatically mean DMARC pass
ARC preserves authentication assessments across intermediaries, but its chain result is separate from a current DMARC result.
Read the playbook →DIAGNOSTIC PLAYBOOKA mailing list changed the subject and broke DKIM
Mailing lists can alter signed fields or body content when adding subject tags and footers.
Read the playbook →DIAGNOSTIC PLAYBOOKA mail gateway footer changes the signed message
A disclaimer or security footer inserted after DKIM signing can invalidate the original body signature.
Read the playbook →DIAGNOSTIC PLAYBOOKOne-click unsubscribe header is missing
An ordinary unsubscribe link and RFC 8058 one-click headers are different mechanisms.
Read the playbook →DIAGNOSTIC PLAYBOOKOne-click unsubscribe headers need DKIM protection
RFC 8058 requires the one-click unsubscribe headers to be covered by a valid DKIM signature.
Read the playbook →DIAGNOSTIC PLAYBOOKOne-click unsubscribe endpoint: GET is not the action
The one-click mechanism uses a defined POST request rather than an ordinary link visit.
Read the playbook →DIAGNOSTIC PLAYBOOKA bounce names a different recipient than the one you sent to
A delivery status notification can report a final recipient that differs from the original address because of aliases or forwarding.
Read the playbook →DIAGNOSTIC PLAYBOOKResent-From is not the same as the DMARC From domain
Resent fields describe reintroduction of a message into transport and do not simply replace the ordinary From identity for DMARC.
Read the playbook →DIAGNOSTIC PLAYBOOKCopying a message can change DKIM verification results
Copying rendered email into a text editor can change line endings, encoding or MIME structure.
Read the playbook →