The method

A domain investigation obtains the IP address the email was sent from and then verifies it against the hosts authorised in the domain’s SPF record. Take the connecting IP from the trusted Received header added by your own mail server, then evaluate the envelope sender domain’s SPF record, including include, a, mx and ip4/ip6 mechanisms.

Reading the result

Pass means the IP was authorised by that domain. Fail or softfail means it was not. Remember SPF checks the envelope sender, which may differ from the visible From address; DMARC alignment connects the two. A message can pass SPF for an attacker’s own lookalike domain, so a pass is not proof of legitimacy.

Recording the evidence

Record the SPF record as retrieved, the evaluation result and the time. Records change, so a later lookup may not reflect what applied when the message was sent.

  • Extract the connecting IP from trusted headers.
  • Identify the envelope sender domain.
  • Evaluate SPF and note the result.
  • Check DMARC alignment with the From domain.

Sources and further reading

RFC 7208, SPFRFC 7489, DMARC
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.