13 FOCUSED PLAYBOOKS

Message forensics

Read headers, forwarding evidence and unsubscribe fields without mistaking clues for proof.

Inspect the original raw message rather than a forwarded screenshot. Headers can contain private addresses, message identifiers and routing information, so redact a separate copy before sharing. Give the most weight to results added by your own trusted receiving infrastructure.

Open the header analyzer
DIAGNOSTIC PLAYBOOK

Which Authentication-Results header should you trust?

Authentication-Results headers are assertions by the system that added them.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Find an email delay using Received headers

Received timestamps can help locate the interval where a message waited, provided the relevant hops and clocks are trustworthy.

Read the playbook →
DIAGNOSTIC PLAYBOOK

From, Reply-To and Return-Path point to different places

These headers serve different purposes: visible authorship, reply destination and bounce routing.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Use Message-ID to trace an email across systems

Message-ID can help correlate a message across logs, but it is not a cryptographic proof of origin or a guarantee of uniqueness.

Read the playbook →
DIAGNOSTIC PLAYBOOK

ARC pass does not automatically mean DMARC pass

ARC preserves authentication assessments across intermediaries, but its chain result is separate from a current DMARC result.

Read the playbook →
DIAGNOSTIC PLAYBOOK

A mailing list changed the subject and broke DKIM

Mailing lists can alter signed fields or body content when adding subject tags and footers.

Read the playbook →
DIAGNOSTIC PLAYBOOK

A mail gateway footer changes the signed message

A disclaimer or security footer inserted after DKIM signing can invalidate the original body signature.

Read the playbook →
DIAGNOSTIC PLAYBOOK

One-click unsubscribe header is missing

An ordinary unsubscribe link and RFC 8058 one-click headers are different mechanisms.

Read the playbook →
DIAGNOSTIC PLAYBOOK

One-click unsubscribe headers need DKIM protection

RFC 8058 requires the one-click unsubscribe headers to be covered by a valid DKIM signature.

Read the playbook →
DIAGNOSTIC PLAYBOOK

One-click unsubscribe endpoint: GET is not the action

The one-click mechanism uses a defined POST request rather than an ordinary link visit.

Read the playbook →
DIAGNOSTIC PLAYBOOK

A bounce names a different recipient than the one you sent to

A delivery status notification can report a final recipient that differs from the original address because of aliases or forwarding.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Resent-From is not the same as the DMARC From domain

Resent fields describe reintroduction of a message into transport and do not simply replace the ordinary From identity for DMARC.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Copying a message can change DKIM verification results

Copying rendered email into a text editor can change line endings, encoding or MIME structure.

Read the playbook →