When an email is delayed, bounces back, or lands in spam for no obvious reason, the quickest way to find out why is to look at its full headers. Headers are hidden technical lines attached to every email that record exactly which servers handled the message, in what order, and what security checks it passed or failed. You do not need to be technical to read them. Once you know which lines to look at, most problems become clear in under a minute.
What Email Headers Are
Every email has two parts: the headers and the body. The body is the message you read. The headers are a log added by each mail server the message passes through on its way from sender to inbox. Your everyday inbox view hides this log because it is not meant for casual reading, but you can reveal it on demand.
How to View Full Headers in Webmail
These steps work the same way regardless of whether your hosting account is on cPanel or DirectAdmin, since both use the same webmail interface for this.
- Log in to your webmail account.
- Open the email you want to inspect.
- Look for an option such as More, Options, or a small menu icon (often three dots) near the top of the open message.
- Select Show Source or View Source. Some webmail themes label this Headers instead.
- A new window or panel will open showing a block of plain text. This is the full header, usually followed by the message body.
If you access your email through a desktop or mobile app such as Outlook or the Gmail app, those apps also have a similar option, usually called View Message Details, Show Original, or Internet Headers, found in the same menu you'd use to reply or forward.
The Header Lines Worth Checking
A full header can look overwhelming because it is long, but only a handful of lines actually matter for troubleshooting.
- Received: there is one of these lines for every server the message passed through, each with a timestamp. Reading them from bottom (oldest) to top (newest) shows the exact path and how long each hop took. A large gap between two timestamps points to where a delay happened.
- Return-Path: the address bounce notifications are sent back to. If this looks unfamiliar or unrelated to the visible sender, the message may be spoofed.
- Authentication-Results: shows whether the message passed or failed SPF, DKIM, and DMARC checks (for example
spf=passordkim=fail). A failure here is a common reason a legitimate-looking email gets rejected or marked as spam. - X-Spam-Status or X-Spam-Score: if present, this shows whether a spam filter scored the message and by how much. Not every server adds this line.
If you are trying to diagnose a bounced message, check the bounce notification itself first. It usually quotes the exact rejection reason from the receiving server near the top, before you even need to dig into the full headers of the original message.
What Headers Commonly Reveal
- Delivery delays: a long stretch of time between two Received lines usually means the message sat queued at an intermediate server, often due to greylisting or the receiving server being temporarily busy.
- Authentication failures: if Authentication-Results shows a failed SPF or DKIM check, the sending domain's DNS records likely need attention, or the message was sent through a service not authorized to send on that domain's behalf.
- Spoofed senders: a mismatch between the visible From name and the Return-Path or the first Received server is a strong sign the message was spoofed rather than genuinely sent from that address.
If headers point to an SPF or DKIM failure on your own domain, see How to Set Up SPF and DKIM Records to Stop Your Emails Going to Spam to fix the underlying DNS records.