Message-ID
Definition
A globally unique identifier assigned to each message by the originating mail server, recorded in the Message-ID header. It is set by the sending MTA and can be forged, but the domain portion often reveals the sending platform or provider.
- Assigned by
- Originating mail server (MTA)
- Recorded in
- Message-ID header
- Forgeable
- Yes
- Useful for
- Revealing sending platform via domain
Common questions
If a Message-ID can be forged, why is it still checked during header analysis?+
Even when forged, the format and domain portion often mismatch the platform conventions of legitimate mail servers, so inconsistencies between the claimed sender and the Message-ID structure can flag spoofing. Genuine Message-IDs also help correlate related messages in a thread.
What distinguishes a Message-ID from a message's Received headers for tracing purposes?+
The Message-ID is a single identifier set once by the originating server, while Received headers form a chain recording each server hop the message passed through. Tracing a sender relies more heavily on the Received chain, with Message-ID used as a supporting, corroborating detail.
Related terms
- DKIM (DomainKeys Identified Mail)
- A cryptographic signing mechanism: the sending server signs the message headers and body with a private key, and the receiving server verifies...
- DMARC (Domain-Based Message Authentication, Reporting, and Conformance)
- A policy layer that requires the domain in the visible From header to align with a domain that passes SPF or DKIM....
- Envelope Sender (Return-Path)
- The address used at the SMTP protocol level for bounce notifications, recorded in the Return-Path header. It is distinct from the display...
- Received Header
- A header line prepended by each mail server that accepts a message in transit, recording the server's own identity, the IP or...
- SPF (Sender Policy Framework)
- A DNS-based mechanism by which a domain owner publishes the list of IP addresses authorised to send mail for that domain. A...