Return-Path

The Return-Path is the envelope sender address of an email, set by the SMTP MAIL FROM command and recorded in a header by the final receiving server. Bounces are sent there, and SPF authenticates its domain.

Deliverability & Email InfrastructureUpdated September 30, 2026

In short

The Return-Path is the hidden address where bounces go, and it is the domain SPF actually checks.

Key points

  1. Under SMTP, the sender states the Return-Path with MAIL FROM; the final delivery server copies it into a Return-Path header [1].
  2. It is also called the envelope sender, MAIL FROM address or 5321.MailFrom, to distinguish it from the visible From header defined in RFC 5322 [1][2][6].
  3. SPF (Sender Policy Framework) evaluates the Return-Path domain, not the From domain, so an SPF pass says nothing about the address the reader sees [3].
  4. For DMARC to pass via SPF, the Return-Path domain must align with the From domain under Domain Alignment rules [4].
  5. Delivery status notifications, the messages behind a Hard Bounce or Soft Bounce, are sent to the Return-Path.
  6. Email service providers often use their own bounce domain by default, which passes SPF but fails alignment unless you set a custom Return-Path.

Envelope sender versus From header

An email has two sender addresses. The first is part of the SMTP conversation: before sending the message, the client issues MAIL FROM with an address, and the receiving servers use it for error reports [1]. The second is the From header inside the message, which is what email programs display [2]. They can differ, and often do. A newsletter might show a friendly From address while using a unique bounce address for each recipient so that returned mail can be matched to a subscriber. When the message reaches its final mailbox, the server records the envelope sender in a Return-Path header at the top of the Email Headers. Reading that header is the easiest way to see which domain a message was really sent under.

The Return-Path and authentication

SPF (Sender Policy Framework) was designed around the envelope sender. The receiver takes the domain from MAIL FROM, fetches that domain's SPF record and checks whether the connecting IP is allowed [3]. Because this domain is invisible to readers, spoofers could pass SPF with a domain they control while forging the From header. DMARC fixes that by requiring alignment: the Return-Path domain must match the From domain, at least at the organizational level under relaxed mode [4]. If an Email Service Provider (ESP) uses its own bounce domain, SPF passes for the provider but does not align with yours, so DMARC must rely on DKIM (DomainKeys Identified Mail) instead. Setting a custom Return-Path on a subdomain, such as bounces.example.com, gives you aligned SPF as a second path to a DMARC pass.

Why bounces matter for deliverability

Every bounce notice goes to the Return-Path, so that address is where a sender learns which recipients do not exist or which messages were refused. RFC 3464 defines the machine-readable format for these delivery status notifications, which lets software tell a permanent failure from a temporary one [5]. Processing them promptly is part of good list hygiene: addresses that hard bounce should be removed and added to a Suppression List, because repeated sends to unknown users raise the Bounce Rate and damage Sender Reputation. Gmail's guidelines tell senders to unsubscribe recipients who bounce repeatedly. When you send from a regular mailbox like Gmail or Outlook, the Return-Path is simply your own address, and bounce notices arrive in your inbox.

Sources
  1. RFC 5321: Simple Mail Transfer Protocol — IETF
  2. RFC 5322: Internet Message Format — IETF
  3. RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1 — IETF
  4. RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) — IETF
  5. RFC 3464: An Extensible Message Format for Delivery Status Notifications — IETF
  6. Set up SPF to identify valid email sources for your Microsoft 365 domain — Microsoft Learn
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →