Any header starting with “X-” is, by definition, unofficial. No IETF standard defines it — it’s whatever the mail client, ESP, or security gateway that added it decided to call it. Chapter 9 is the field guide to that unregulated territory.
X-Mailer identifies the software that composed the message. X-Originating-IP reveals a sender’s actual IP address — a header increasingly withheld by major providers like Gmail and Outlook for privacy reasons, which the chapter explains alongside why its absence is itself informative during an investigation.
ESP-specific headers get real coverage too — campaign IDs, list-unsubscribe tracking, and the assorted tagging headers marketing platforms attach for their own analytics, none of which follow a shared naming convention across providers. And because there’s no registry for any of this, the chapter also covers gateway-injected security headers.
This chapter reads less like a spec summary and more like field notes from thousands of real headers, because that’s genuinely what it is.