The Email Header Analysis: How to Diagnose Deliverability Problems
Your open rates dropped 40% overnight and you have no idea why. The answer is sitting inside every email you've ever sent โ in the headers most people never look at.
Your open rates dropped 40% overnight and you have no idea why. The answer is sitting inside every email you've ever sent โ buried in the headers that 99% of cold emailers have never once read.
Email header analysis for deliverability diagnosis is one of those skills that separates people who guess their way through inbox problems from people who fix them in 20 minutes. I've diagnosed hundreds of deliverability issues this way โ misconfigured SPF records, broken DKIM signatures, spam filter rejections, relay hops adding blacklisted IPs โ all of it visible if you know what you're looking at.
This is the guide I wish I had three years ago.
What Email Headers Actually Are (And Why They Matter)
Every email you send carries two parts: the body (what you see) and the headers (what mail servers see). Headers are metadata โ a chain of instructions and stamps that document exactly where your email came from, how it traveled, and what authentication checks it passed or failed.
Here's the counterintuitive part: spam filters make their decision based almost entirely on headers, not your email copy. You can spend hours crafting the perfect cold email, but if your headers show a broken DKIM signature or a relay through a flagged IP, Gmail's filters have already made up their mind before they read a single word.
For a deeper look at the authentication side of this, read Why Your Cold Emails Are Landing in Spam: A Deep Dive into Email Authentication โ it covers SPF, DKIM, and DMARC from the ground up.
How to Access Email Headers in 60 Seconds
Before you can diagnose anything, you need to pull the raw headers. Here's how to do it across the most common platforms:
Gmail:
- Open the email
- Click the three dots (โฎ) in the top right
- Select "Show original"
- You'll see the full raw header + body
Outlook:
- Open the email
- File โ Properties
- Headers are in the "Internet headers" box
Apple Mail:
- View โ Message โ All Headers
Once you have the raw headers, copy everything above the first blank line (that blank line separates headers from the body). Paste it into Google's Message Header Analyzer or MXToolbox's header analyzer.
But honestly, reading them manually is faster once you know what to look for.
Stop paying monthly
Cleanmails โ self-hosted cold email infrastructure.
The Email Header Analysis Deliverability Diagnosis: What to Look For
Here are the seven fields I check in order, every single time.
1. Authentication Results (The Most Important Section)
Look for a block that starts with Authentication-Results:. This is where the receiving server documents whether your email passed or failed each authentication check.
Authentication-Results: mx.google.com;
dkim=pass header.i=@yourdomain.com header.s=selector1;
spf=pass (google.com: domain of you@yourdomain.com designates 12.34.56.78 as permitted sender);
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=yourdomain.com
What you want to see: pass on all three โ DKIM, SPF, and DMARC.
What's bad:
dkim=failโ Your DKIM signature is broken or missingspf=softfailโ Your sending IP isn't in your SPF recorddmarc=failโ Both SPF and DKIM failed alignment
A dmarc=fail is often a death sentence for deliverability. Gmail and Microsoft 365 will either send it straight to spam or reject it outright depending on your DMARC policy.
Run your domain through the SPF/DKIM/DMARC Checker right now if you haven't verified your records recently. I've seen campaigns tank because someone updated their DNS and accidentally broke an SPF record โ this tool catches it in 30 seconds.
2. Received Headers (The Delivery Chain)
Every server that touches your email adds a Received: header. They stack from bottom (first) to top (last). Reading them bottom-to-top shows you the exact path your email traveled.
Received: from mail.yourdomain.com (mail.yourdomain.com [12.34.56.78])
by mx.google.com with ESMTPS id ...
for <prospect@theirdomain.com>;
Mon, 15 Jan 2024 09:23:41 -0800
What to check:
- Number of hops: More than 3-4 hops is suspicious and adds latency
- IP addresses: Copy each IP and check it against MXToolbox Blacklist Checker. One blacklisted relay kills your deliverability even if your own IP is clean
- Timestamps: Huge gaps between hops (>30 seconds) often indicate a server under load or flagged for review
3. The X-Spam Headers
Many mail servers add X-Spam-Status or X-Spam-Score headers that tell you exactly how their spam filter scored your email.
X-Spam-Status: No, score=1.8 required=5.0
X-Spam-Checker-Version: SpamAssassin 3.4.6
X-Spam-Report:
* 0.8 HTML_MESSAGE BODY: HTML included in message
* 0.5 MISSING_HEADERS Missing To: header
* 0.5 RCVD_IN_DNSWL_NONE RBL: Sender listed at dnswl.org, no trust
This is gold. SpamAssassin and similar filters literally show you point-by-point why they're flagging your email. A score above 5.0 typically means spam folder. I've seen campaigns with scores of 8+ because someone used a shared SMTP relay that had RCVD_IN_SBL (Spamhaus Block List) hits.
4. Message-ID Format
Legitimate emails have a Message-ID that looks like this:
Message-ID: <unique-string@yourdomain.com>
If your Message-ID shows a third-party domain (not your sending domain), that's a red flag. It means your email is routing through a third-party SMTP relay and the headers are exposing it. Some spam filters score this negatively.
This is one reason I run Cleanmails with its built-in SMTP โ the Message-ID always reflects my actual sending domain, not some shared relay's infrastructure.
5. Return-Path Alignment
Return-Path: <bounce@yourdomain.com>
From: You <you@yourdomain.com>
For DMARC to pass, the Return-Path domain needs to align with the From domain. If you're using a third-party tool that sets Return-Path: bounce@tool-vendor.com while your From shows you@yourdomain.com, you'll get DMARC misalignment failures.
This is an extremely common problem with tools that use shared bounce-handling infrastructure. Check it.
6. Content-Type and Encoding Headers
Content-Type: multipart/alternative; boundary="000000000000abc12345"
If your email is text/html only with no text/plain version, that's a spam signal. Legitimate email clients send both. Every cold email tool worth using sends multipart/alternative automatically โ but verify it's happening.
7. X-Mailer and User-Agent Headers
Some tools expose themselves here:
X-Mailer: Mailchimp Mailer
Certain X-Mailer values are on spam filter watch lists because they're associated with bulk sending. Ideally, this header is either absent or shows something neutral.
A Real Diagnosis Example
Here's a situation I ran into last year. Open rates on a client's campaign dropped from 34% to 11% in a single week. Nothing in the copy changed. Nothing in the list changed.
Pulled the headers on a test send. Found this:
Authentication-Results: mx.google.com;
dkim=fail (signature did not verify);
spf=pass;
dmarc=fail (p=QUARANTINE)
And in the Received chain, there was a relay IP that hit two Spamhaus blocklists.
The DKIM failure turned out to be a DNS propagation issue โ they'd rotated their DKIM keys but the old selector was still in the header. The relay IP issue was because their ESP had silently moved them to a shared IP pool that had reputation problems.
Fix: Updated DKIM selector in the sending config, switched to a dedicated IP. Open rates recovered to 31% within 5 days.
Total diagnosis time: 22 minutes.
The 30-Minute Deliverability Audit Using Headers
Here's a repeatable process you can run right now:
- Send a test email to a Gmail account, a Microsoft 365 account, and your own domain
- Pull headers from all three (each server will give you different spam scoring)
- Check Authentication-Results โ all three should show
dkim=pass,spf=pass,dmarc=pass - Run each IP in the Received chain through a blacklist checker
- Note the X-Spam-Score if present โ anything above 3.0 warrants investigation
- Verify Return-Path alignment matches your From domain
- Check for multipart/alternative in Content-Type
For a broader weekly routine that includes this check, see The Weekly Cold Email Health Check: 7 Things to Review Every Monday โ it puts header analysis into a repeatable maintenance schedule.
Also run your list through the Bulk Email Verifier if you're seeing high bounce rates alongside deliverability drops. High bounces damage your sender reputation and the two problems compound each other.
The Surprising Insight Nobody Talks About
Here's something that took me a long time to understand: your deliverability problems are almost never about your content.
The cold email industry has spent years obsessing over spam words, subject line formulas, and copy frameworks. And yes, Why 93% of Cold Emails Never Get Opened (And How to Fix It) makes the case that copy matters. It does.
But in my experience diagnosing campaigns, the split is roughly:
- 70% of deliverability problems โ authentication failures, blacklisted IPs, relay issues (all visible in headers)
- 20% โ sending volume/warm-up issues
- 10% โ content/spam word triggers
You can use the Email Spam Word Checker to rule out content issues in under a minute. If your copy checks out clean, the problem is almost certainly in the headers.
What Good Headers Look Like: A Reference
| Header Field | What You Want | Red Flag |
|---|---|---|
dkim= |
pass |
fail, none |
spf= |
pass |
fail, softfail |
dmarc= |
pass |
fail, quarantine |
| Return-Path domain | Matches From domain | Third-party domain |
| Received chain IPs | Clean (0 blacklists) | Any blacklist hit |
| X-Spam-Score | Below 3.0 | Above 5.0 |
| Content-Type | multipart/alternative |
text/html only |
| Relay hops | 2-3 max | 5+ |
Final Thoughts
Email header analysis is not glamorous. It's not a growth hack. It's plumbing โ and most people ignore their plumbing until the pipes burst.
The practitioners who consistently hit 35-45% open rates aren't necessarily better copywriters. They're better engineers. They check their headers after every major send. They know what dmarc=fail means before their open rates tank. They treat deliverability like infrastructure, not an afterthought.
Start with one test send today. Pull the headers. Run the checklist above. I'd bet money you find at least one thing worth fixing.
Related:
Stop paying monthly for cold email.
Cleanmails โ self-hosted, unlimited everything, $200 one-time.



