The main headers are the elements visible to any user and constitute the first layer of information we must review when analyzing an email. Although they seem simple, each one can provide key clues about the legitimacy of the message.

From (Sender)

The From field shows the address that apparently sends the email. It is one of the easiest elements to forge. An attacker can use a similar domain, a visually identical name, or even a completely fabricated address.
Article image

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

To (Recipient)

The To field indicates who receives the message. Although it is usually correct, it can also reveal if the email has been sent in bulk or if an unexpected distribution list has been used.

Subject

The Subject is the title of the message. Attackers often use urgency, alarms, or emotional messages to force a quick reaction.

Date (Declared Date)

The Date field shows the date and time declared by the sending server. It does not always coincide with the real time.

Reply-To (Reply Address)

The Reply-To field indicates which address the response will be sent to. It is one of the most commonly used elements in fraud.

Message-ID (Unique Identifier)

The Message-ID is a unique identifier generated by the sending server. It is very difficult to forge correctly.

Return-Path (Technical Return Address)

The Return-Path is used by servers to manage bounces. It does not always match the visible sender.

Conclusion

The main headers are the first line of defense in email analysis. Although many can be manipulated, reviewing them allows for the detection of obvious inconsistencies before moving on to more technical layers such as SPF, DKIM, or DMARC. In the next article, we will delve into these authentication headers and how they validate the sender's identity. SPF, DKIM y DMARC: qué son y cómo detectan correos falsos

Email Authentication Headers