How to View and Analyze Email Headers in 138 Enterprise Email: Technical Guide for Administrators
How to View and Analyze Email Headers in 138 Enterprise Email
Who Needs to View Email Headers
Enterprise IT administrators, security teams, and foreign trade professionals using 138 Enterprise Email may need to examine email headers for:
- Delivery troubleshooting: Identifying why emails are delayed or rejected
- Authentication verification: Checking SPF, DKIM, and DMARC results
- Security investigation: Analyzing suspicious or phishing emails
- Compliance auditing: Verifying message routing and handling
Step-by-Step: Accessing Email Headers
Web Client Method
- Log into your 138 Enterprise Email web interface
- Open the email you want to examine
- Click the three-dot menu (⋮) in the top-right corner
- Select "View Message Source" or "Show Original"
- The full header information will display in a new window
Desktop Client Methods
- Outlook: Open message → File → Properties → Internet Headers
- Thunderbird: Open message → View → Message Source
- Apple Mail: Open message → View → Message → Raw Source
Mobile Access
While mobile apps typically don't show full headers directly, you can:
- Forward the suspicious email to your web account
- Access the web version from your mobile browser
- Follow the web client steps above
Key Header Fields to Analyze
When examining headers, focus on these critical sections:
Authentication Results:
- Received-SPF: Shows SPF (Sender Policy Framework) validation status
- DKIM-Signature: Indicates DKIM (DomainKeys Identified Mail) authentication
- Authentication-Results: Combined authentication results including DMARC
Routing Information:

- Received: Shows each server that handled the message, with timestamps
- Return-Path: Indicates where bounce messages should be sent
- Message-ID: Unique identifier for the message
Security Indicators:
- X-138-Antivirus: Shows virus scanning results (if enabled)
- X-138-Antispam: Indicates spam scoring and filtering actions
Practical Header Analysis Scenarios
Scenario 1: Delivery Failure Investigation
When emails fail to reach recipients, examine headers for:
- Authentication failures (SPF/DKIM/DMARC rejects)
- Blacklisted IP addresses in Received headers
- Incorrect routing through unexpected servers
Scenario 2: Security Incident Response
For suspected phishing or compromised accounts:
- Verify actual sending source versus displayed sender
- Check for mismatched Reply-To addresses
- Look for suspicious routing patterns
- Cross-reference with login and sending logs in your 138 admin portal
According to 138's security documentation, retaining original emails and headers for administrator analysis is recommended practice for security investigations.
Technical Boundaries and Limitations
- Header information can be forged or manipulated by advanced attackers
- Some intermediate servers may strip or modify headers
- Mobile clients often provide limited header access
- Historical headers may not be available after certain retention periods
For complete investigation, combine header analysis with:
- 138 Enterprise Email admin portal logs
- Authentication configuration verification
- End-user interviews and additional evidence collection
Next Steps for Enterprise Teams
- Train appropriate staff on header analysis techniques
- Establish investigation procedures for delivery and security issues
- Regularly verify your domain's SPF, DKIM, and DMARC configurations
- Document common header patterns for your organization's normal traffic
For complex delivery issues or security incidents, 138's official support can provide additional logging and analysis assistance beyond what's visible in standard headers.
For detailed information on account management, password recovery, and security configurations, administrators should refer to the official 138 Enterprise Email FAQ and security knowledge base. These resources cover procedures such as resetting passwords via bound mobile phones, configuring SPF/DKIM/DMARC for authentication, and responding to security incidents like account compromises or phishing emails.


