Email headers
44 signals in this category. Every entry links to a full explanation, severity tier, and false-positive notes.
What most signals in this category mean
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
- Auto-generated emailwarning
auto-submitted - Brand Domain, DKIM Absentthreat
brand-dkim-none - Brand Domain, DKIM Verifiedwarning
brand-dkim-verified - Read-Receipt Harvestingwarning
disposition-notification-request - DKIM signed by different domainwarning
dkim-alignment-mismatch - Reputation laundering: DKIM signed by 3rd-party domain + bulk marketing body, no List-Unsubscribethreat
dkim-domain-mismatch-with-bulk-body - DMARC p=none Brand Spoofthreat
dmarc-policy-none-high-value-brand - Excessive Mail Routing Hopsthreat
excessive-received-hop-chain - Excessive mail relay hops (6+ Received headers)threat
excessive-received-hops - Fake DMARC report lurethreat
fake-dmarc-report-spear-phishing - Header injection characters in subject/reply-tothreat
header-injection-in-subject-or-reply-to - Reply-To freemail mismatchthreat
header-mismatched-reply-to-freemail - IPv6 sender, no DKIM/SPF pass (reputation-bypass)threat
ipv6-no-reputation-no-dkim - Malformed Message-ID header (spam indicator)threat
malformed-message-id - Malformed Message-ID header (RFC 5322 violation)threat
malformed-message-id-header - Message-ID on free webmail but From is corporate (forgery)threat
message-id-freewebmail-mismatch - ARC seal absent on forwarded email (spoofed relay)threat
missing-arc-seal-validation - No Message-ID header (spam/phishing indicator)threat
missing-message-id - Bulk mail missing unsubscribe headerwarning
no-unsubscribe-bulk-precedence - Bulk mailing listwarning
precedence-bulk - Precedence: bulk/list from a free-webmail sender — spammer using mailing-list classification without real mailer infrastructurethreat
precedence-bulk-from-free-webmail - Mailing listwarning
precedence-list - Large gap between Received: header timestamps (relay delay)threat
received-header-timestamp-gap - SPF Comment-Injection "(pass)" Fakethreat
received-spf-comment-injection-pass-fake - SPF Whitespace Evasionthreat
received-spf-whitespace-evasion - Reply-To routes corporate sender to free webmail — payroll/vendor/CEO fraud signaturethreat
reply-to-corporate-to-freemail - Reply-To / From domain mismatchthreat
reply-to-differs-from-from-domain - Reply-To base domain differs from From address base domain — classic phishing misdirection.warning
reply-to-domain-divergence - Reply-To domain differs from sender (suspicious)warning
reply-to-mismatch - Reply-To header has multiple addresses — harvest-ring fan-outthreat
reply-to-multiple-addresses - Bounce domain differs from senderwarning
return-path-domain-mismatch - Single mail hop — no infrastructurethreat
single-received-hop-no-list-header - Authenticated SMTP, No DKIMthreat
smtp-auth-submitted-but-no-dkim - Envelope/From Domain Driftwarning
smtp-envelope-from-domain-drift - SPF passes on cousin domain, From claims brandthreat
spf-pass-cousin-domain - Bulk/automated mail (Exchange)warning
x-auto-response-suppress - Microsoft spam filter: definite spamthreat
x-forefront-antispam-scl-high - Fake Google Senderwarning
x-google-smtp-source-absent - Spam kit mailer software detectedthreat
x-mailer-version-outdated-spam-kit - Tor Exit Node Originating IPthreat
x-originating-ip-tor-exit - X-PHP-Originating-Script header — sent via PHP mail() from a shared-hosting bulk mailerthreat
x-php-originating-script - Server flagged as spam (X-Spam-Flag: YES)threat
x-spam-flag - SpamAssassin score ≥ 5.0threat
x-spam-score-numeric-high - Server flagged as spam (X-Spam-Status: Yes)threat
x-spam-status-yes
Want to see them in action?
Connect your Gmail in 10 seconds and Gorganizer will show you exactly which signals fired on every email — colour-coded by severity, with full explanations.
Get started