Gmail shows authentication data to the recipient


Yesterday Gmail rolled out some changes to their interface. One of the changes is that they are now showing end users authentication results in the user screen.
It’s really the next step in email authentication, showing the results to the end user.
So how does Google do this? Google is checking both SPF and DKIM. If mail is authenticated and the authentication matches the from address then they display the email as:
mail from steve to me
If we click on “details” for that message, we find more specific information.
full details of message showing signing domain and spf domainIn this case the mail went through our outgoing mailserver to gmail.
Mailed-by indicates that the message passed SPF and that the IP address is a valid source of mail from
Signed-by shows the domain in the DKIM d=. In this case, we signed with the subdomain That’s what happens when you sign using the domain in the From address (or a subdomain of it).
For a lot of bulk senders, though, their mail is signed using their ESP’s domain instead.  In that case Gmail shows who signed the mail as well as the from address.

And when we click on “details” for that message we see:
3rd party signature detailsThis is an email from a sender using Madmimi as an ESP. Madmimi is handling both the SPF authentication and the DKIM authentication.
As an aside, this particular  sender has a high enough reputation that Gmail is offering me an unsubscribe option in their interface.
Gmail is distinguishing between first party and third party signatures in authentication. If the mail is authenticated, but the authentication appears to be handled by a separate entity, then Gmail is alerting recipients to that fact.
What does this mean for bulk senders?
For senders that are signing with a domain that matches their From: domain, there is no change. Recipients will not see any mention of your ESP in the headers.
However, if you are using an ESP that is signing your mail with a domain they own, then your recipients will see that information displayed in the email interface. If you don’t want this to be displayed by Gmail, then you will need to move to first party signing. Talk to your ESP about this. If they’re unsure of how to manage it, you can point them to DKIM Core for an Email Service Provider.
Gmail blogpost about the changes
Gmail help page about authentication results

About the author


This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • But if I use a third party ESP and that I change my DNS, I don’t get this “via”thing right ?

  • If you have the ESP sign with your domain in the d= then you don’t get the “via” in the headers, as best I can tell.

  • Joey, take a look at Mailgun ( – we support fully custom DKIM/SPF and your traffic will appear native to your domain. Besides, we support a lot more than just that! 🙂

  • […] Gmail tells all If you know that Gmail subscribers make up a significant portion of your audience and you are using a third-party ESP or mailing platform, Gmail may detect that the email was sent via a mail service and display this information to the user: You can manage this by ensuring your emails are authenticated with an SPF record or DKIM signature. More information can be found from Gmail or Laura Atkin’s deliverability blog. […]

  • Another option is email quality assurance testers. Some can test for DKIM signatures that will or won’t work properly. I’ve worked with a few but my favorite so far is EmailSuccess. It has the largest, most encompassing set of tests for issues in HTML, images and links, content words and phrases most often flagged by the new provider spam/sorting filters – and yes, even issues with domain signatures in the From lines.
    Also, EmailSuccess is free while many of the others are paid services and don’t offer tests as numerous and comprehensive in an all in one package. I set my URL as the EmailSuccess website so you can click on my name to access it if you want to try it.

By laura

Recent Posts


Follow Us