Email authentication
Check SPF, DKIM and DMARC for an email
Authentication results show whether the server that sent an email was allowed to send for its domain. Gmail doesn’t show them on the page, so Fromensics reads them from headers you paste.
What you’ll see
How we know
Sign-in results aren’t visible in Gmail
Add the message headers to check SPF, DKIM, and DMARC too.
Add
Add the headers
In Gmail
- Open ⋮ on the message and choose Show original.
- Copy everything on that page.
- In the Fromensics report, open More and choose Paste headers, paste, and scan.
In Outlook on the web
- Open ⋯ More actions → View → View message source (View message details on Microsoft 365).
- Copy it all, paste it into Fromensics, and scan.
When it’s done you’ll see “Scan complete. Authentication now uses the pasted original.” The pasted text is checked on your device and isn’t sent anywhere.
What the results mean
| You’ll see | What it means |
|---|---|
| SPF authentication passed | The sending server was allowed to send for that domain. |
| DKIM authentication failed | The domain’s signature on the message didn’t check out. |
| DMARC authentication did not fully pass | The result was a soft fail, not a clean pass. |
| ARC authentication was not present | The message carried no result for that method. |
| DMARC authentication could not be checked | The headers didn’t include a result Fromensics could read. |
A failed result means the email can’t be treated as low risk, whatever else looks fine.
Questions
Does a pass mean the email is genuine?
No. A pass proves the domain’s own server sent it. A lookalike domain can pass its own checks, so look at who the domain is too.
Why doesn’t Fromensics read the headers automatically?
Gmail and Outlook don’t show them on the page, and Fromensics doesn’t ask for access to your mailbox. Pasting keeps the headers on your device.