Envelope Sender (Return-Path)
Definition
The address used at the SMTP protocol level for bounce notifications, recorded in the Return-Path header. It is distinct from the display From address and is what SPF checks. Attackers often spoof the From but not the Return-Path, which creates an inconsistency that header analysis exposes.
- Header
- Return-Path
- Level
- SMTP protocol, not the display From address
- Checked by
- SPF authentication
Common questions
Why do attackers often spoof the From header but not the Return-Path?+
Spoofing the visible From address deceives the recipient reading the message, but forging a Return-Path that also passes SPF for the sending domain is harder, since SPF validates the Return-Path domain against the sending server's authorised IPs.
How does a mismatch between From and Return-Path help an investigator?+
A From address claiming to be a trusted organisation paired with a Return-Path pointing to an unrelated domain is a strong indicator of spoofing, useful evidence even before deeper header or authentication-result analysis.
Related terms
- DKIM (DomainKeys Identified Mail)
- A cryptographic signing mechanism: the sending server signs the message headers and body with a private key, and the receiving server verifies...
- DMARC (Domain-Based Message Authentication, Reporting, and Conformance)
- A policy layer that requires the domain in the visible From header to align with a domain that passes SPF or DKIM....
- Message-ID
- A globally unique identifier assigned to each message by the originating mail server, recorded in the Message-ID header. It is set by...
- Received Header
- A header line prepended by each mail server that accepts a message in transit, recording the server's own identity, the IP or...
- SPF (Sender Policy Framework)
- A DNS-based mechanism by which a domain owner publishes the list of IP addresses authorised to send mail for that domain. A...