Email Header Fields Explained: From, To, Reply-To and More
On this page
What Email Headers Are
Every email message contains two parts: the headers and the body. The headers carry metadata about the message, including who sent it, who received it, when it was sent, what the subject is and how it was routed across the internet. The body is the actual content the recipient reads.
Most email clients hide the full headers and show only the basics: From, To, Subject and Date. But behind that simplified view, email headers contain a detailed record of the message's origin, routing and authentication.
Understanding header fields is useful for anyone working with email files. When you extract email addresses from EML or MSG files, the addresses in the headers are part of what gets extracted.
Header Fields That Contain Email Addresses
From
The From field identifies who sent the message. It typically contains a display name and an email address:
From: Alice Smith <alice@example.com>
Every email has exactly one From field. This is the address the recipient sees as the sender.
To
The To field lists the primary recipients. It can contain one or more addresses:
To: bob@example.com, carol@example.org
Or with display names:
To: Bob Jones <bob@example.com>, Carol Wu <carol@example.org>
CC (Carbon Copy)
The CC field lists recipients who receive a copy of the message. All recipients (To and CC) can see each other's addresses:
CC: dave@example.net
BCC (Blind Carbon Copy)
The BCC field lists recipients whose addresses are hidden from other recipients. In most cases, the BCC field is stripped from the message before delivery, so it typically does not appear in saved EML or MSG files. If it does appear, it would only be in the sender's own saved copy.
Reply-To
The Reply-To field specifies where replies should be directed, which may differ from the From address:
Reply-To: support@example.com
This is common in mailing lists and automated messages where the sender address is a no-reply address, but replies should go to a monitored inbox.
Sender
The Sender field indicates the person or system that actually transmitted the message, when it differs from the From address:
Sender: assistant@example.com
From: CEO <ceo@example.com>
This field appears when someone sends mail on behalf of another person, such as an executive assistant sending from a shared mailbox.
Return-Path
The Return-Path (also called the envelope sender) is the address where bounce notifications are delivered:
Return-Path: <bounces@example.com>
This address often differs from the From address. Email marketing platforms typically use their own return-path addresses to handle bounces.
Header Fields for Routing and Authentication
These fields do not typically contain addresses you would want to extract for contact purposes, but they are important for understanding how email works.
Received
Received headers are added by each mail server that handles the message, recording a trail of the message's journey:
Received: from mail.example.com (mail.example.com [192.0.2.1])
by mx.example.org with ESMTP id abc123
for <bob@example.org>; Mon, 7 Oct 2026 10:30:00 +0000
Messages typically have multiple Received headers, one for each server hop. They are read from bottom to top, with the oldest at the bottom.
Message-ID
A unique identifier assigned by the sender's mail system:
Message-ID: <unique-id-12345@mail.example.com>
This is not an email address, even though it looks similar. The angle brackets and the @ sign follow the same syntax, but a Message-ID identifies a specific message, not a mailbox.
In-Reply-To and References
These fields link a message to the thread it belongs to by referencing the Message-IDs of previous messages:
In-Reply-To: <original-message-id@mail.example.com>
References: <original-message-id@mail.example.com> <reply-id@mail.example.com>
Again, these look like email addresses but are message identifiers. They may appear in extraction results because they follow the same format as email addresses.
Authentication headers
Several header fields record the results of authentication checks:
- Authentication-Results: summarises SPF, DKIM and DMARC check results.
- DKIM-Signature: contains the DKIM cryptographic signature.
- Received-SPF: records the SPF check result.
These may contain domain names and email-like strings but are not addresses for contact purposes.
How Headers Relate to Extraction
When you extract email addresses from EML or MSG files using Email Extractor, the tool reads supported message headers and the message body. This means addresses from the From, To, CC, Reply-To and other header fields are included in the results, along with any addresses that appear in the body text (such as email addresses in signatures, forwarded messages or inline contact information).
What gets extracted
- Addresses from standard header fields (From, To, CC, Reply-To, Sender, Return-Path).
- Addresses in the message body text.
- Addresses in email signatures.
- Addresses in forwarded message text that is part of the body.
What does not get extracted
- Attachment contents. If an email has a PDF, spreadsheet or other file attached, Email Extractor does not open the attachment. Save attachments separately and extract from them individually.
- Message-IDs, In-Reply-To and References values may appear in results because they follow the email address format. Review extracted results and remove any that are clearly message identifiers rather than real addresses (they often contain strings like
message-idor unusually long random characters).
Filtering results
After extraction, review the results for:
System addresses. Headers contain addresses like mailer-daemon@example.com, postmaster@example.com and bounce-handling addresses that are not useful as contacts.
No-reply addresses. The From field of automated messages often uses a no-reply address. These are not contactable.
Duplicate addresses. The same address may appear in the From field of one message and the To field of another. Email Extractor removes duplicates automatically using case-insensitive matching.
Download as CSV with sources to see which EML or MSG file each address was found in. This helps you identify the context around each address and decide whether it is useful for your purposes.
Viewing Full Headers
If you want to inspect the full headers of an email before extracting:
In most email clients, look for an option like "Show original," "View source," "View message headers" or "Message properties." The exact location varies by client.
In an EML file, open it in a plain text editor. The headers are the lines at the top of the file, before the first blank line. Everything after that blank line is the body.
In an MSG file, headers are stored in a binary format. You typically need Outlook or a dedicated MSG viewer to read them.