The method
A domain investigation obtains the IP address the email was sent from and then verifies it against the hosts authorised in the domain’s SPF record. Take the connecting IP from the trusted Received header added by your own mail server, then evaluate the envelope sender domain’s SPF record, including include, a, mx and ip4/ip6 mechanisms.
Reading the result
Pass means the IP was authorised by that domain. Fail or softfail means it was not. Remember SPF checks the envelope sender, which may differ from the visible From address; DMARC alignment connects the two. A message can pass SPF for an attacker’s own lookalike domain, so a pass is not proof of legitimacy.
Recording the evidence
Record the SPF record as retrieved, the evaluation result and the time. Records change, so a later lookup may not reflect what applied when the message was sent.
- Extract the connecting IP from trusted headers.
- Identify the envelope sender domain.
- Evaluate SPF and note the result.
- Check DMARC alignment with the From domain.
