Help us take down a fraudulent domain Forward the suspicious email with full headers so we can act fast
Domain Takedown Assistance

We need a copy of the suspicious email with full headers

Someone is using a fraudulent look-alike domain to impersonate a legitimate organization. To file a takedown and stop the abuse, we need a copy of the suspicious email with its full, original email headers intact.

⚠ Important: Simply forwarding the email the normal way does not include headers. You need to use the specific steps below for your email provider. This takes about 60 seconds.

What are email headers? Every email carries hidden routing information (timestamps, server addresses, and authentication results) that most people never see. This metadata is the digital fingerprint we need to prove where the fraudulent email actually came from, who sent it, and which infrastructure to target for a takedown.

Gmail (Web Browser)

Get full headers from Gmail

Use these steps in Gmail on a desktop or laptop browser. These steps do not apply to the Gmail mobile app.

  1. Open the suspicious email in Gmail so you can see its full contents on screen.
  2. In the top-right corner of the email, click the three vertical dots (the "More" menu). It is next to the Reply arrow.
  3. From the dropdown menu, click Show original.
  4. A new tab will open showing the raw email with all headers. Click the Copy to clipboard button near the top of that page.
  5. Compose a new email to us. Paste the copied content into the body of the email and send it to the address we provided you.

Alternative: On the "Show original" page you can also click Download Original to save the email as an .eml file. You can then attach that file to a new email and send it to us.

Outlook on the Web (Office 365)

Get full headers from Outlook

Use these steps in Outlook on the web (outlook.office.com or outlook.live.com) in a desktop or laptop browser.

  1. Open the suspicious email in Outlook on the web so you can read its full contents.
  2. At the top-right of the message, click the three horizontal dots (the "More actions" button: sometimes shown as …).
  3. In the dropdown menu, click View › View message source.
  4. A panel or new window will appear with the full raw message and headers. Select all of the text (Ctrl+A on Windows or Cmd+A on Mac), then copy it (Ctrl+C or Cmd+C).
  5. Compose a new email to us. Paste the copied content into the body and send it to the address we provided you.

Can't find "View message source"? In some Outlook versions the path is the three-dot menu, then View message details. The result is the same, a panel showing the full raw headers.

Why do we need full headers?

A normal forwarded email strips out the technical routing data. Full headers preserve the original metadata we need to pursue a domain takedown. Specifically, headers give us:

  • Originating server IP addresses: where the email was actually sent from.
  • SPF, DKIM, and DMARC results: whether the sending domain passed or failed email authentication.
  • Full routing path: every server the email passed through on its way to you.
  • Timestamps: precise dates and times used for the abuse report.
  • Return-path and envelope sender, the real "from" address, which is often different from what you see.

This information is critical evidence for filing abuse complaints with domain registrars, hosting providers, and email service providers to get fraudulent infrastructure shut down.

Common mistakes to avoid

✗ Don't just forward the email normally. A regular forward strips out the headers we need. You must use the "Show original" or "View message source" steps above.

✗ Don't take a screenshot. Screenshots don't include any header data and can't be used for a takedown filing.

✗ Don't delete the email. Keep the original email in your inbox until we confirm we have everything we need.

✓ Do send us the full raw text: either pasted into a new email or attached as an .eml file. Both work.

Questions or need help?

If you have any trouble with these steps, reply to the email we sent you or contact us directly. We are happy to walk you through it.