Skip to content
Signet
Blog

What is email? The message, the envelope, and the record

An email looks like one thing: a letter with a sender, a subject and a body. It is really two: an envelope that mail servers read, and a message that people read. Most of email security lives in the gap between them.
6 min read
  • Identity

Two standards, two audiences

Email is defined by two separate standards, and they were written for different readers. The Simple Mail Transfer Protocol, SMTP, describes how one server hands a message to another (RFC 5321). The Internet Message Format describes what the message itself looks like: the headers, the blank line, the body (RFC 5322).

The first is the envelope. The second is the letter inside it. A postal letter works the same way: the address on the envelope decides where it goes, and the letterhead inside is what the recipient reads. Nothing forces the two to agree.

The envelope

When a server sends mail, it opens a connection to the receiving server and has a short conversation. Two commands in that conversation form the envelope:

  • MAIL FROM, the return address. It is where bounces go, which is why it is also called the bounce address or Return-Path.
  • RCPT TO, the recipient. One per address the message is delivered to.

The recipient never sees the envelope directly. The receiving server records part of it in headers it adds, and then the envelope is gone.

The message

After the envelope, the sending server transmits the message: headers, a blank line, and the body. The headers are what a mail client shows you.

The start of a message
From: Accounts <[email protected]>
To: [email protected]
Subject: Your invoice for October
Date: Mon, 5 Oct 2026 09:14:02 +0000
Message-ID: <[email protected]>

Please find attached...

The From line there is the one people read and trust. It is also text the sender typed. SMTP carries it without checking it, and the envelope's MAIL FROM can name a completely different domain.

On its own, the From line proves nothing. Anyone can write any name and address into it.

Why that gap matters

Email was designed in the 1970s and 1980s for a network of institutions that knew each other. Proving who sent a message was not a problem it set out to solve. Phishing, invoice fraud and spoofed password resets all live in the gap between what the envelope says and what the From line claims.

Three standards close it, one layer at a time:

  • SPF lets a domain publish which servers may use it in the envelope’s MAIL FROM (RFC 7208).
  • DKIM lets a domain sign the message with a key it publishes in DNS, so a receiver can check the content was not altered and who vouched for it (RFC 6376).
  • DMARC ties those checks to the visible From domain, and lets that domain say what receivers should do when the checks fail (RFC 9989).

None of them changes how email looks. They give a receiving server a way to tell whether the From line can be believed.

What an email address is

An address has two halves around the @: a local part, which only the receiving domain interprets, and a domain, which the rest of the internet uses to find the receiving server. The domain half is what all of the authentication above is about: it is the part a domain owner controls, publishes records for, and can prove.

To see the envelope and the headers of a real message, and whether its From line holds up, send one to our message check. It shows what a receiving server sees.

Sources

  1. RFC 5321: Simple Mail Transfer Protocol
  2. RFC 5322: Internet Message Format
  3. RFC 7208: Sender Policy Framework (SPF)
  4. RFC 6376: DomainKeys Identified Mail (DKIM)
  5. RFC 9989: Domain-based Message Authentication, Reporting, and Conformance (DMARC)

See it on your own domain. The scan reads all twelve record types in one lookup, free and without an account.

Scan a domain